CVE-2025-8219: fallo de gravedad media en Shanghai Lingdang Information Technology…
Shanghai Lingdang Information Technology Lingdang CRM HTTP POST Request tabdetail_moduleSave_dxkp.php sql injection
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 67% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been rated as critical. This issue affects some unknown processing of the file /crm/crmapi/erp/tabdetail_moduleSave_dxkp.php of the component HTTP POST Request Handler. The manipulation of the argument getvaluestring leads to sql injection. The attack may be initiated remotely. Upgrading to version 8.6.5.2 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+. We strongly advise all customers to upgrade to the current version (v8.6.5.2), which includes this fix and additional security enhancements."
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Productos afectados
Shanghai Lingdang Information Technology · Lingdang CRMCVEs relacionadas — Shanghai Lingdang Information Technology…
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-0461MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php path traversalEPSS 0.9%CVE-2025-9140MEDIUMShanghai Lingdang Information Technology Lingdang CRM tabdetail_moduleSave.php sql injectionEPSS 0.5%CVE-2025-0462MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php sql injectionEPSS 0.5%CVE-2025-5005MEDIUMShanghai Lingdang Information Technology Lingdang CRM index_event.php server-side request forgeryEPSS 0.5%CVE-2025-0463MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php unrestricted uploadEPSS 0.4%CVE-2025-8908MEDIUMShanghai Lingdang Information Technology Lingdang CRM event.php sql injectionEPSS 0.3%