← back
CVE-2025-0333

leiyuxi cy-fast listData sql injection

CVSS 5.3 MEDIUMEPSS 0.6%CWE-74CWE-89
A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
leiyuxi · cy-fast

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →