CVE-2025-52390

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 16:15

Updated : 2025-08-01 18:15


NVD link : CVE-2025-52390

Mitre link : CVE-2025-52390


JSON object : View

Products Affected

No product.

CWE

No CWE.