Vulnerability Description
A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cszcms | Csz Cms | <= 1.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/Huu1j/CSZ_CMS-exploit/blob/main/csz-cms-vulnerability-analysiExploitThird Party Advisory
FAQ
What is CVE-2025-63608?
CVE-2025-63608 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated ...
How severe is CVE-2025-63608?
CVE-2025-63608 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63608?
Check the references section above for vendor advisories and patch information. Affected products include: Cszcms Csz Cms.