PT-2025-35904 · Unknown · Apprain Cmf

Rafael Pedrero

·

Published

2025-09-04

·

Updated

2025-09-04

·

CVE-2025-41033

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions appRain CMF version 4.0.5
Description An SQL injection vulnerability exists that allows an attacker to retrieve, create, update, and delete the database. This is possible through the data%5BPage%5D%5Bname%5D parameter in the /apprain/page/manage-dynamic-pages/create API endpoint.
Recommendations As a temporary workaround, restrict access to the /apprain/page/manage-dynamic-pages/create API endpoint to minimize the risk of exploitation. Sanitize or validate the data%5BPage%5D%5Bname%5D parameter to prevent SQL injection attacks.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41033

Affected Products

Apprain Cmf