Junglewise Threat Intelligence

CVE-2025-7631: Tumeva Prime News Software SQL injection

CVE-2025-7631 · Severity: high · CVSS 8.6 · Published 2026-02-17

Executive brief

Tumeva Prime News Software, a digital news publishing platform, contains a security flaw that allows unauthorized individuals to manipulate its database. By exploiting this vulnerability, an attacker could potentially access sensitive information, modify website content, or disrupt the availability of the news service. This could lead to data theft, reputational damage through site defacement, or significant operational downtime.

Technical details

An SQL injection vulnerability exists in Tumeva Prime News Software due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application over the network. Successful exploitation enables the attacker to execute arbitrary SQL queries against the backend database, potentially leading to unauthorized data retrieval, modification, or a denial-of-service condition. The vulnerability is addressed in version 1.0.2.

Affected products

  • Tumeva Internet Technologies Software Prime News Software v1.0.1 to v1.0.2 (exclusive)

Timeline

  • 2026-02-17: disclosed
  • 2026-02-17: advisory: Initial advisory published by TR-CERT (USOM)
  • 2026-06-05: other: Last modified in NVD database

References