Junglewise Threat Intelligence

CVE-2025-7714: Global Interactive Design Media Software CMS SQL injection

CVE-2025-7714 · Severity: high · CVSS 7.5 · Published 2026-01-29

Executive brief

A critical security flaw has been identified in the Global Interactive Design Media Software Content Management System (CMS), which is used to manage and publish digital content. This vulnerability allows an attacker to remotely execute commands on the underlying server, potentially leading to a complete takeover of the website and its data. Such an exploit could result in the theft of sensitive information, website defacement, or a total disruption of services.

Technical details

An SQL injection vulnerability exists in the Global Interactive Design Media Software Inc. Content Management System (CMS) due to improper neutralization of special elements in SQL commands. The flaw is located within the CMS core and allows an unauthenticated remote attacker to perform command line execution via the SQL injection vector. According to the CVSS 3.1 score of 9.8, the attack is low complexity, requires no privileges, and has a high impact on confidentiality, integrity, and availability. The issue affects all versions up to and including 21072025. Organizations should check for patches or updates from the vendor to mitigate this risk.

Affected products

  • Global Interactive Design Media Software Inc. Content Management System (CMS) through 21072025

Timeline

  • 2026-01-29: disclosed: Initial publication of the CVE record.
  • 2026-01-29: advisory: Advisory released by the Computer Emergency Response Team of the Republic of Turkey (USOM).

References

Related threats