Authorization Bypass Through User-Controlled SQL Primary Key
CVE-2025-56556
Summary
An issue was discovered in Subrion CMS, allowing authenticated administrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- HIGH
- LOW
- NONE
CWE-566 - Authorization Bypass Through User-Controlled SQL Primary Key
The software uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.
Advisory Timeline
- Published