CVE-2025-44830

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
References
Link Resource
https://gist.github.com/LTLTLXEY/e00ec21b730742ef432a7a560cd9b70a Third Party Advisory
https://github.com/3xxx/engineercms/issues/90 Exploit Third Party Advisory Issue Tracking
https://github.com/3xxx/engineercms/issues/90 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:engineercms_project:engineercms:*:*:*:*:*:*:*:*

History

13 Jun 2025, 13:49

Type Values Removed Values Added
Summary
  • (es) EngineerCMS v1.02 a v.2.0.5 tiene una vulnerabilidad de inyección SQL en la interfaz /project/addprojtemplet.
First Time Engineercms Project engineercms
Engineercms Project
CPE cpe:2.3:a:engineercms_project:engineercms:*:*:*:*:*:*:*:*
References () https://gist.github.com/LTLTLXEY/e00ec21b730742ef432a7a560cd9b70a - () https://gist.github.com/LTLTLXEY/e00ec21b730742ef432a7a560cd9b70a - Third Party Advisory
References () https://github.com/3xxx/engineercms/issues/90 - () https://github.com/3xxx/engineercms/issues/90 - Exploit, Third Party Advisory, Issue Tracking

12 May 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/3xxx/engineercms/issues/90 - () https://github.com/3xxx/engineercms/issues/90 -
CWE CWE-89

12 May 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 16:15

Updated : 2025-06-13 13:49


NVD link : CVE-2025-44830

Mitre link : CVE-2025-44830

CVE.ORG link : CVE-2025-44830


JSON object : View

Products Affected

engineercms_project

  • engineercms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')