Back

CRITICAL

SQL injection vulnerability in DM Corporative CMS

Published Jun 10, 2025

Description

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the Dmacroweb team in version 2025.01.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jun 10, 2025
Updated Jun 10, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Jun 10, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a