Junglewise Threat Intelligence

CVE-2026-3325: CRM Sistemas MegaCMS SQL injection in get_provincias endpoint

CVE-2026-3325 · Severity: info · CVSS 10 · Published 2026-04-29

Executive brief

MegaCMS, a software platform used for managing reservation systems, ticketing, and online sales, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to gain unauthorized access to the underlying database. This could lead to the theft of sensitive customer data, modification of records, or a complete disruption of the ticketing and sales services.

Technical details

A SQL injection (SQLi) vulnerability exists in MegaCMS v12.0.0 due to inadequate validation and sanitization of user-supplied input. The flaw is located in the 'id_territorio' parameter of the '/web_comunications/cms/get_provincias' endpoint, which processes POST requests immediately after registration form submission. An unauthenticated remote attacker can manipulate this parameter to execute arbitrary SQL queries against the backend database. This can result in full data exfiltration, modification of database contents, or administrative bypass. Users are advised to update to the latest available version provided by CRM Sistemas de Fidelización.

Affected products

  • CRM Sistemas de Fidelización MegaCMS 12.0.0

Timeline

  • 2026-04-29: advisory: Initial advisory published by INCIBE-CERT
  • 2026-04-29: disclosed: CVE-2026-3325 published to NVD

References