CVE-2026-3325 CRITICAL

CVE-2026-3325: SQL injection in MegaCMS by CRM Sistemas de Fidelización

Vendor Crm Sistemas De Fidelización
Product MegaCMS
Weakness CWE-89 · SQLi
Published April 29, 2026
Last update April 29, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L

What the vulnerability does

01Description

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Specifically, via a POST request, the “id_territorio” parameter, used immediately after the registration form is submitted, could be manipulated by an unauthenticated attacker to execute arbitrary SQL queries.

Key dates

02Disclosure timeline

April 29, 2026 CVE published
April 29, 2026 Record updated