Executive brief
SemCms, a content management system used for building e-commerce and corporate websites, contains a security vulnerability in its product management component. An attacker with basic user access can exploit this flaw to interact directly with the website's database. This could lead to the unauthorized viewing of sensitive information, modification of site data, or potentially gaining full administrative control over the database.
Technical details
A SQL injection vulnerability exists in SemCms versions up to and including 5.0. The flaw is located in the 'lgid' parameter within the SEMCMS_Products.php component. The application fails to properly sanitize or neutralize special elements in the SQL command, allowing a remote attacker with low-level privileges to inject malicious SQL queries. Successful exploitation can lead to unauthorized data retrieval, data manipulation, and in some configurations, the acquisition of database administrator (DBA) permissions. A proof-of-concept has been identified in public disclosures.
Affected products
- SemCms SemCms <= 5.0
Timeline
- 2025-07-14: advisory: Initial NVD publication date