CVE-2025-10351: SQL injection vulnerability in Melis Platform
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10351?
CVE-2025-10351 has a high severity rating due to its potential for database manipulation through SQL injection.
How do I fix CVE-2025-10351?
To fix CVE-2025-10351, update the Melis Platform to the latest version that addresses this SQL injection vulnerability.
Who is affected by CVE-2025-10351?
CVE-2025-10351 affects users of the Melis Platform, specifically those utilizing the melis-cms module.
What type of vulnerability is CVE-2025-10351?
CVE-2025-10351 is classified as an SQL injection vulnerability.
What can an attacker do with CVE-2025-10351?
An attacker exploiting CVE-2025-10351 can retrieve, create, update, and delete databases through the vulnerable endpoint.