First published: Tue May 13 2025(Updated: )
SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
DomainsPRO |
The vulnerability has been fixed by the DomainsPRO team in version 1.3.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40628 is considered a critical SQL injection vulnerability that can lead to unauthorized database access.
Fixing CVE-2025-40628 involves validating and sanitizing user inputs for the 'd' parameter in the '/article.php' endpoint.
CVE-2025-40628 affects DomainsPRO version 1.2.
Exploitation of CVE-2025-40628 could allow attackers to retrieve, create, update, and delete databases.
You can determine vulnerability to CVE-2025-40628 by checking if your system uses DomainsPRO 1.2 and testing the 'd' parameter for SQL injection flaws.