Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges.  This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.
History

Mon, 02 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Pro3w
Pro3w pro3w Cms
Vendors & Products Pro3w
Pro3w pro3w Cms

Sat, 28 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Description Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges.  This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.
Title SQL Injection in Pro3W CMS
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2026-02-27T13:51:53.006Z

Updated: 2026-02-27T14:19:48.682Z

Reserved: 2026-01-09T15:36:57.745Z

Link: CVE-2025-15498

cve-icon Vulnrichment

Updated: 2026-02-27T14:19:44.027Z

cve-icon NVD

Status : Received

Published: 2026-02-27T14:16:27.860

Modified: 2026-02-27T14:16:27.860

Link: CVE-2025-15498

cve-icon Redhat

No data.