Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23366 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges. |
Tue, 05 Aug 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saurus
Saurus saurus Cms |
|
| Vendors & Products |
Saurus
Saurus saurus Cms |
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-01T17:30:08.528Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52390
Updated: 2025-08-01T17:27:53.960Z
Status : Deferred
Published: 2025-08-01T16:15:42.203
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52390
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:56:34Z
EUVD