SQL Injection Vulnerability in Aem Solutions CMS by Aem Solutions
CVE-2025-5434
Key Information:
- Vendor
Aem Solutions
- Status
- Vendor
- CVE Published:
- 2 June 2025
Badges
What is CVE-2025-5434?
A vulnerability exists in the Aem Solutions CMS up to version 1.0, specifically identified in the /page.php file. Malicious actors can exploit this flaw through manipulations of the ID argument, resulting in SQL injection. The attack can be executed remotely, significantly enhancing its potential threat. Public awareness of this exploit has been raised, and despite early disclosures to the vendor, no response has been received. Protecting systems from this vulnerability is essential to safeguard sensitive data and maintain security integrity.
Affected Version(s)
CMS 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved