9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Description
Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker.
Versions 4.0 and above are not affected.
Versions 4.0 and above are not affected.
Basic Information
ID
CVE-2025-7385
Source
CERT-PL
Published
Sep 4, 2025 at 12:05
Modified
Sep 4, 2025 at 12:06
Affected Product
Vendor
Concept Intermedia
Product
GOV CMS
Affected Versions
Concept Intermedia GOV CMS 0