DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application.
History

Fri, 03 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Ddsn
Ddsn cm3 Acora Content Management System
CPEs cpe:2.3:a:ddsn:cm3_acora_content_management_system:10.1.1:*:*:*:*:*:*:*
Vendors & Products Ddsn
Ddsn cm3 Acora Content Management System

Mon, 03 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 21:00:00 +0000

Type Values Removed Values Added
Description SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter. DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application.

Wed, 15 Jan 2025 22:45:00 +0000

Type Values Removed Values Added
Description SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-03T18:27:25.443Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2025-22964

cve-icon Vulnrichment

Updated: 2025-01-16T16:49:49.551Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-15T23:15:10.650

Modified: 2025-10-03T12:53:39.053

Link: CVE-2025-22964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.