Junglewise Threat Intelligence

CVE-2025-51655: SemCms SQL injection in SEMCMS_Quanxian.php

CVE-2025-51655 · Severity: medium · CVSS 5.4 · Published 2025-07-14

Technologies: SEMCMS. Vendors: SEMCMS.

Executive brief

SemCms, a content management system used for building e-commerce and corporate websites, contains a security flaw in its permission management component. An attacker with basic user access can exploit this vulnerability to interact directly with the website's database. This could lead to the unauthorized viewing or modification of sensitive business data and customer information.

Technical details

A SQL injection vulnerability exists in SemCms versions up to and including 5.0. The flaw is located in the 'pid' parameter within the SEMCMS_Quanxian.php file, which fails to properly neutralize special elements before using them in a SQL command (CWE-89). An attacker with low-privileged network access can send specially crafted requests to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive data from the database, modify records, or potentially gain administrative (DBA) permissions depending on the database configuration. A proof-of-concept has been identified in public disclosures.

Affected products

  • SemCms SemCms <= 5.0

Timeline

  • 2025-07-14: disclosed: Initial disclosure of the vulnerability
  • 2025-07-14: advisory: NVD published CVE-2025-51655

References

Related threats