PT-2026-22340 · Pro3W Cms · Pro3W Cms
Jacek Czepil
·
Published
2026-02-27
·
Updated
2026-02-27
·
CVE-2025-15498
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pro3W CMS versions prior to January 2026
Description
Pro3W CMS is susceptible to SQL injection attacks. Insufficient input validation within the login form permits an unauthenticated attacker to circumvent authentication and obtain administrative access. The vulnerability exists in version 1.2.0. The
login form is the entry point for this attack, and the vulnerability stems from improper neutralization of input. The vulnerable parameter is not explicitly identified.Recommendations
Update to versions released in January 2026 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pro3W Cms