Home

Description

A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path resulting in Blind SQL Injection. This issue was fixed in versions above 8.0.

PUBLISHED Reserved 2025-10-29 | Published 2026-03-02 | Updated 2026-03-02 | Assigner CERT-PL




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 8.0
affected

Credits

Jarosław Wieczorek finder

Paweł Berus finder

Kacper Gendosz finder

Karolina Buchnat finder

References

cert.pl/posts/2026/03/CVE-2025-12462/

cve.org (CVE-2025-12462)

nvd.nist.gov (CVE-2025-12462)

Download JSON