6.9
CVE-2025-40661 - Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting theย option parameter equal to 0, 1 or 2 in /administer/selectionnode/selection.asp.
6.9
CVE-2025-40660 - Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting theย option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&cod=1&networks=0.
6.9
CVE-2025-40659 - Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting theย option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.
6.9
CVE-2025-40658 - Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting theย option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelection.asp.
9.3
CVE-2025-40657 - SQL injection vulnerability in DM Corporative CMS
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.
9.3
CVE-2025-40656 - SQL injection vulnerability in DM Corporative CMS
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.
9.3
CVE-2025-40655 - SQL injection vulnerability in DM Corporative CMS
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp.
9.3
CVE-2025-40654 - SQL injection vulnerability in DM Corporative CMS
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp.
0.0
CVE-2025-49786 -
Not used
0.0
CVE-2025-49789 -
Not used