Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0.
NOTE: The vendor was contacted and it was learned that the product is not supported.
NOTE: The vendor was contacted and it was learned that the product is not supported.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6742 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported. |
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-25-0072 |
|
History
Thu, 20 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Title | SQLi in CM Informatics' CM News | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2025-03-20T15:09:41.232Z
Reserved: 2024-12-02T13:16:09.235Z
Link: CVE-2024-12016
Updated: 2025-03-20T15:05:08.825Z
Status : Deferred
Published: 2025-03-20T08:15:11.547
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-12016
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD