VORANT. Threat Intelligence Sign in Get the full feed

Pro3W CMS Login Bypass via SQL Injection

medium vulnerability

An unauthenticated SQL injection flaw in Pro3W CMS lets attackers bypass login and gain admin access.

CERT Polska coordinated disclosure of CVE-2025-15498, a SQL injection vulnerability in Pro3W CMS affecting version 1.2.0. The flaw stems from improper sanitization of input submitted through the login form, allowing an unauthenticated attacker to bypass authentication entirely and obtain administrative privileges on affected installations.

CERT Polska notes that the vendor did not respond during the coordination process, so the exact range of affected versions could not be confirmed. However, the issue is expected to be fixed in versions released from January 2026 onward. The vulnerability was reported by researcher Jacek Czepil and disclosed through CERT Polska's coordinated vulnerability disclosure process. There is no indication of active exploitation in the wild at this time.

Mentioned in this report

Vulnerabilities CVE-2025-15498

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-15498

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free