This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pro3w
Pro3w pro3w Cms |
|
| Vendors & Products |
Pro3w
Pro3w pro3w Cms |
Sat, 28 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges. This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later. | |
| Title | SQL Injection in Pro3W CMS | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-02-27T14:19:48.682Z
Reserved: 2026-01-09T15:36:57.745Z
Link: CVE-2025-15498
Updated: 2026-02-27T14:19:44.027Z
Status : Awaiting Analysis
Published: 2026-02-27T14:16:27.860
Modified: 2026-03-02T20:30:10.923
Link: CVE-2025-15498
No data.
OpenCVE Enrichment
Updated: 2026-03-02T12:07:13Z