Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection.

This issue affects SEM-PMP: through 23042026.
Published: 2026-07-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a classic SQL injection caused by improper neutralization of special characters in SQL statements, allowing an attacker to inject operating‑system commands through the database server. Successful exploitation grants the attacker arbitrary command execution on the host running the database, leading to loss of confidentiality, integrity, and availability of the application and underlying systems. This weakness is classified as CWE‑89.

Affected Systems

Semtek Informatics Software Consulting Trade Ltd. Co. SEM‑PMP versions up to and including 23042026 are vulnerable. No fixed version is documented; administrators should upgrade to a later release when a vendor patch becomes available.

Risk and Exploitability

The CVSS score of 9.8 flags critical severity, while the EPSS score of <1% suggests a low exploitation probability at present. However, the ability to execute arbitrary commands elevates the risk markedly. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, requiring the attacker to deliver malicious input to a reachable application endpoint, potentially via web or API interfaces, without necessarily needing authentication.

Generated by OpenCVE AI on July 29, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify and apply any vendor-supplied patch or upgrade SEM‑PMP to a release beyond 23042026.
  • Restrict external access to the application by using firewalls, VPNs, or network segmentation, limiting exposure of the vulnerable interfaces to trusted networks.
  • Configure the database to run with the least privilege necessary and enable comprehensive logging and monitoring of SQL activity to detect potential injection attempts and facilitate rapid incident response.

Generated by OpenCVE AI on July 29, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Semtek
Semtek sem-pmp
Vendors & Products Semtek
Semtek sem-pmp

Fri, 10 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026.
Title SQLi in Semtek Informatics' SEM-PMP
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-10T19:06:18.464Z

Reserved: 2026-04-08T14:18:28.380Z

Link: CVE-2026-5801

cve-icon Vulnrichment

Updated: 2026-07-10T19:05:54.122Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')