Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Dmacroweb team in version 2025.01.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17652 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp. |
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acc
Acc dm Corporative Cms |
|
| CPEs | cpe:2.3:a:acc:dm_corporative_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Acc
Acc dm Corporative Cms |
|
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp. | |
| Title | SQL injection vulnerability in DM Corporative CMS | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-10T19:59:50.416Z
Reserved: 2025-04-16T08:38:13.918Z
Link: CVE-2025-40657
Updated: 2025-06-10T19:59:47.166Z
Status : Analyzed
Published: 2025-06-10T10:15:28.043
Modified: 2025-10-22T14:00:13.857
Link: CVE-2025-40657
No data.
OpenCVE Enrichment
No data.
EUVD