CVE-2025-51653: SQL Injection
Published Jul 14, 2025
·Updated
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMSct.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms<=5.0
Event History
Jul 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51653?
CVE-2025-51653 is assessed as a critical severity vulnerability due to its SQL injection potential.
2
How do I fix CVE-2025-51653?
To fix CVE-2025-51653, you should validate and sanitize the 'pid' parameter before processing it in SEMCMS_ct.php.
3
What is the impact of CVE-2025-51653?
The impact of CVE-2025-51653 can lead to unauthorized access to the database and potential data manipulation.
4
What versions are affected by CVE-2025-51653?
CVE-2025-51653 affects all versions of SemCms up to and including version 5.0.
5
Is CVE-2025-51653 publicly known?
Yes, CVE-2025-51653 is publicly known and documented in security databases.