CVE-2025-52390 Information
Aug 02, 2025
cve
Description
Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the prepareSearchQuery() method in FulltextSearch.class.php. The application directly concatenates user-supplied input ($search_word) into SQL queries without sanitization allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges.
Reference
https://github.com/sauruscms/Saurus-CMS-Community-Edition/blob/d886e5b0c1e2b42cd74e2184e7c81c720cd9de6b/classes/FulltextSearch.class.php#L331 https://github.com/theharshkothari/vulnerability-research/blob/main/CVE-2025-52390.md
Related CNNVD
CNNVD-202508-057 (Published: 2025-08-01)
Share on: