PT-2025-35905 · Unknown · Apprain Cmf

Rafael Pedrero

·

Published

2025-09-04

·

Updated

2025-09-04

·

CVE-2025-41034

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions appRain CMF version 4.0.5
Description An SQL injection flaw exists in appRain CMF version 4.0.5. This flaw allows an attacker to retrieve, create, update, and delete the database through the data%5BPage%5D%5Bname%5D parameter in the /apprain/page/manage-static-pages/create/ API endpoint.
Recommendations As a mitigation, restrict access to the /apprain/page/manage-static-pages/create/ API endpoint. Sanitize or validate the data%5BPage%5D%5Bname%5D parameter before using it in database queries.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-41034

Affected Products

Apprain Cmf