Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges.
This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pro3w
Pro3w pro3w Cms |
|
| Vendors & Products |
Pro3w
Pro3w pro3w Cms |
Sat, 28 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges. This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later. | |
| Title | SQL Injection in Pro3W CMS | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-02-27T14:19:48.682Z
Reserved: 2026-01-09T15:36:57.745Z
Link: CVE-2025-15498
Updated: 2026-02-27T14:19:44.027Z
Status : Received
Published: 2026-02-27T14:16:27.860
Modified: 2026-02-27T14:16:27.860
Link: CVE-2025-15498
No data.