Vulnerability Description
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint.
Related Weaknesses (CWE)
References
- https://github.com/ivansmc00/CVE-2025-10351-POC
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-meli
FAQ
What is CVE-2025-10351?
CVE-2025-10351 is a documented vulnerability. SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through t...
How severe is CVE-2025-10351?
CVSS scoring is not yet available for CVE-2025-10351. Check NVD for updates.
Is there a patch for CVE-2025-10351?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.