Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 8.0
affected
Description
A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in multiple parameters resulting in Blind SQL Injection. This issue was fixed in versions above 8.0.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 8.0
Credits
Jarosław Wieczorek
Paweł Berus
Kacper Gendosz
Karolina Buchnat
References
cert.pl/posts/2026/03/CVE-2025-12462/