Executive brief
Semtek SEM-PMP, a project management platform, contains a critical security flaw that allows unauthorized individuals to execute commands on the underlying server. By exploiting this vulnerability, an attacker could gain full control over the system, potentially leading to the theft of sensitive project data, service disruption, or further attacks on the corporate network. This issue requires no special user interaction or login credentials to exploit.
Technical details
A SQL injection vulnerability exists in Semtek Informatics SEM-PMP through version 23042026 due to improper neutralization of special elements in SQL commands (CWE-89). The vulnerability is particularly severe as it facilitates Command Line Execution (RCE) via the SQL injection vector. An unauthenticated remote attacker can exploit this flaw with low complexity, requiring no user interaction. Successful exploitation grants the attacker the ability to execute arbitrary commands on the host operating system with the privileges of the database service, potentially leading to a full system compromise.
Affected products
- Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP through 23042026
Timeline
- 2026-07-10: advisory: NVD published the CVE record based on TR-CERT data.