SemCms SQL Injection Vulnerability in Products Page

Vulnerability

A SQL injection vulnerability has been identified in SemCms version 5.0. The issue arises in the Products page (SEMCMS_Products.php), specifically through the lgid parameter. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Added: Jul 14, 2025, 5:18 PM
Updated: Jul 14, 2025, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
9.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.