216.73.216.133

CVE-2025-2625

· Published 22/03/2025 20:15 · Modified 22/03/2025 20:15

Labels: CVE-2025-2625 2025-03-22CVE-2025-2625CWE-74[email protected]

Essential information

Published
22/03/2025 20:15
Modified
22/03/2025 20:15
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument orderField/orderDirection leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
westboy / cicadascms cpe:2.3:a:westboy:cicadascms:*:*:*:*:*:*:*:*

References