← Back to browse · API

CVE-2025-50567

Severity
CRITICAL
CVSS
10.0
EPSS
0.00633
Risk score
40.22
CISA KEV
No
PoC
No
Published
2025-08-19
Modified
2026-07-05
First seen
2026-08-07
Aliases
EUVD-2025-25172, GHSA-89C8-63Q9-H76J
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-25172

Description

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution.

References