Skip to main content

Authorization Bypass Through User-Controlled SQL Primary Key

CVE-2025-56556

Severity Low
Score 3.8/10

Summary

An issue was discovered in Subrion CMS, allowing authenticated administrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-566 - Authorization Bypass Through User-Controlled SQL Primary Key

The software uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.

Advisory Timeline

  • Published