Description
Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 4.0
Credits
Kamil Szczurowski
Robert Kruczek
References
cert.pl/posts/2025/09/CVE-2025-7385
sam3.pl/strona-305-za_co_nas_cenia_redaktorzy.html