DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/padayali-JD/CVE-2025-22964 |
![]() ![]() |
History
Fri, 03 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ddsn
Ddsn cm3 Acora Content Management System |
|
CPEs | cpe:2.3:a:ddsn:cm3_acora_content_management_system:10.1.1:*:*:*:*:*:*:* | |
Vendors & Products |
Ddsn
Ddsn cm3 Acora Content Management System |
Mon, 03 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Thu, 23 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter. | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application. |
Wed, 15 Jan 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-03T18:27:25.443Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2025-22964

Updated: 2025-01-16T16:49:49.551Z

Status : Analyzed
Published: 2025-01-15T23:15:10.650
Modified: 2025-10-03T12:53:39.053
Link: CVE-2025-22964

No data.

No data.