CVE-2025-3800
19.04.2025, 12:15
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
| Vendor | Product | Version |
|---|---|---|
| wcms | wcms | 11.0 |
𝑥
= Vulnerable software versions