PT-2025-35903 · Unknown · Apprain Cmf

Rafael Pedrero

·

Published

2025-09-04

·

Updated

2025-09-04

·

CVE-2025-41032

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions appRain CMF version 4.0.5
Description An SQL injection flaw exists in appRain CMF version 4.0.5. This flaw allows an attacker to retrieve, create, update, and delete the database through the data%5BAdmin%5D%5Busername%5D parameter in the /apprain/admin/manage/add/ API endpoint.
Recommendations As a mitigation, restrict access to the /apprain/admin/manage/add/ API endpoint. Sanitize or validate the data%5BAdmin%5D%5Busername%5D parameter before processing it.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-41032

Affected Products

Apprain Cmf