PT-2026-22340 · Pro3W Cms · Pro3W Cms

Jacek Czepil

·

Publicado

2026-02-27

·

Atualizado

2026-02-27

·

CVE-2025-15498

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pro3W CMS versions prior to January 2026
Description Pro3W CMS is susceptible to SQL injection attacks. Insufficient input validation within the login form permits an unauthenticated attacker to circumvent authentication and obtain administrative access. The vulnerability exists in version 1.2.0. The login form is the entry point for this attack, and the vulnerability stems from improper neutralization of input. The vulnerable parameter is not explicitly identified.
Recommendations Update to versions released in January 2026 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15498

Produtos afetados

Pro3W Cms