CVE ID | CVE-2025-7385 |
Publication date | 04 September 2025 |
Vendor | Concept Intermedia |
Product | GOV CMS |
Vulnerable versions | All before 4.0 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Concept Intermedia GOV CMS software and participated in coordination of its disclosure.
The vulnerability CVE-2025-7385: Input from search
query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker.
Vendor did not provide information about vulnerable versions. Versions 4.0 and above are not affected.
Credits
We thank Kamil Szczurowski and Robert Kruczek for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.