A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
Title | SiempreCMS user_search_ajax.php sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-09T00:32:09.580Z
Reserved: 2025-09-08T14:35:26.010Z
Link: CVE-2025-10115

No data.

Status : Received
Published: 2025-09-09T01:15:31.760
Modified: 2025-09-09T01:15:31.760
Link: CVE-2025-10115

No data.

No data.