VYPR

Dm Corporative CMS

by Dmacroweb

CVEs (9)

  • CVE-2025-40657CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.

  • CVE-2025-40656CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.

  • CVE-2025-40655CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp.

  • CVE-2025-40654CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp.

  • CVE-2025-40662HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.

  • CVE-2025-40661HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/selection.asp.

  • CVE-2025-40660HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&…

  • CVE-2025-40659HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

  • CVE-2025-40658HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelection.asp.