An issue was discovered in SEMCMS 3.8. SEMCMSInquiry.php allows AID[] SQL Injection because the class.phpmailer.php injectchecksql protection mechanism is incomplete.
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
A vulnerability in /include/webcheck.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.