External risk intelligence

Melis Platform melis-cms SQL Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-10351

The vulnerability exists in a content management system (CMS) module. CMS platforms are typically deployed as public-facing web applications to manage website content, making the underlying web endpoints and API parameters, such as the identified template retrieval path, commonly accessible from the internet in standard deployments.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical SQL injection vulnerability has been identified in the Melis CMS module of the Melis platform. This flaw could potentially allow unauthorized access to manipulate or extract sensitive database information, impacting the integrity and confidentiality of data. The main concern is confirming the relevance and exposure of this vulnerability within our specific environment.

  • Unauthenticated attackers can alter or view database contents.
  • Matters because database integrity and confidentiality are paramount.
  • Assess if Melis CMS is in use and confirm exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. This could allow them to manipulate the database, potentially leading to unauthorized data access or modifications.

  • No authentication or user interaction needed.
  • SQL injection via 'idPage' parameter.
  • Full database control possible.

Live Threat

Current exploitation, exposure, and threat context

The melis-cms module's 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint is susceptible to SQL injection, potentially allowing unauthorized database manipulation. This could affect system data, user data, and service behavior when the endpoint is accessible.

  • Database integrity and content.
  • Via SQL injection over the network.
  • Unauthorized data access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in the Melis CMS module likely impacts teams responsible for the Melis platform, including application owners and potentially infrastructure or platform teams managing its deployment. The first practical step is to identify all instances of the Melis platform, determine their internet-facing exposure and business criticality, and then assign ownership for remediation planning.

  • Platform or application owners should investigate.
  • Verify internet-facing Melis platform instances.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Melis platform?

Melis is a technology platform that includes a content management system (CMS). The melis-cms module is a specific component used to manage website content, templates, and digital assets. Developers and organizations use it to build and maintain the structure and appearance of their web-based projects.

What does SQL injection mean for CVE-2025-10351?

This CVE involves CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain English, the system fails to properly filter input provided by users. Because of this, an attacker can insert malicious database commands into the 'idPage' parameter, effectively tricking the application into running unauthorized database operations.

How is this vulnerability triggered?

The vulnerability is triggered by sending a specially crafted web request to the specific '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Importantly, no authentication or prior user interaction is required to initiate the attack. Requests that do not target this specific parameter or endpoint do not trigger the flaw.

Is my instance affected by this vulnerability?

According to Halo Surface Signal, this vulnerability is highly relevant if you use the Melis CMS. Because CMS platforms are designed to manage website content, they are typically deployed as public-facing applications. This means the affected endpoint is often reachable from the internet, making it easier for remote attackers to interact with the vulnerable parameter.

What should I do if I run the Melis platform?

Start by identifying all instances of the Melis platform within your environment to determine where it is deployed. Prioritize verifying which of these are exposed to the internet. Once you have an inventory, coordinate with the application owners to assess the business impact and begin the process of planning for remediation.

References