CVE-2025-67829 identifies a critical SQL injection vulnerability (CWE-89) in Mura CMS versions prior to 10.1.14, specifically within the beanFeed.cfc getQuery sortDirection component. This flaw carries a CVSSv3.1 score of 9.8 (Critical), indicating it can be exploited remotely over the network with low attack complexity and no privileges or user interaction required. Successful exploitation could lead to a complete compromise of data confidentiality, integrity, and system availability. Currently, there is no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage regarding this vulnerability are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1.4CPE matchmatch criteria | cpe:2.3:a:murasoftware:mura_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.