Junglewise Threat Intelligence

CVE-2025-51658: SemCms SQL injection in SEMCMS_InquiryView.php

CVE-2025-51658 · Severity: medium · CVSS 5.4 · Published 2025-07-14

Technologies: SEMCMS. Vendors: SEMCMS.

Executive brief

SemCms, a content management system used for building corporate and e-commerce websites, contains a security flaw in its inquiry viewing component. An attacker with basic user access can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive business information or the modification of website data.

Technical details

A SQL injection vulnerability exists in SemCms versions up to and including 5.0. The flaw is located in the 'ID' parameter of the 'SEMCMS_InquiryView.php' script, which fails to properly sanitize user-supplied input before using it in a database query. An authenticated attacker with low-level privileges can send specially crafted network requests to execute arbitrary SQL commands. Successful exploitation allows the attacker to read, modify, or delete data within the database, potentially gaining full database administrator (DBA) permissions. No official patch has been confirmed in the provided advisory, though users are advised to validate all input parameters.

Affected products

  • SemCms SemCms <= 5.0

Timeline

  • 2025-07-14: disclosed: Initial vulnerability disclosure and CVE assignment.
  • 2025-07-14: advisory: NVD published the vulnerability details.

References

Related threats