SQL Injection Vulnerability in SemCms 5.0 by SemCms
CVE-2025-51660

5.4MEDIUM

Key Information:

Vendor

SemCms

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-51660?

SemCms version 5.0 has been identified to be vulnerable to a SQL injection flaw via the 'lgid' parameter within the 'SEMCMS_Products.php' file. This vulnerability may allow an attacker to execute arbitrary SQL code, compromising the integrity of the database and potentially exposing sensitive information. Proper input validation and sanitization measures should be implemented to mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.