CVE-2025-8908: fallo de gravedad media en Shanghai Lingdang Information Technology…
Shanghai Lingdang Information Technology Lingdang CRM event.php sql injection
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 75% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this issue is some unknown functionality of the file crm/WeiXinApp/yunzhijia/event.php. The manipulation of the argument openid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.6.5 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+."
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Shanghai Lingdang Information Technology · Lingdang CRMCVEs relacionadas — Shanghai Lingdang Information Technology…
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-0461MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php path traversalEPSS 0.9%CVE-2025-9140MEDIUMShanghai Lingdang Information Technology Lingdang CRM tabdetail_moduleSave.php sql injectionEPSS 0.5%CVE-2025-0462MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php sql injectionEPSS 0.5%CVE-2025-5005MEDIUMShanghai Lingdang Information Technology Lingdang CRM index_event.php server-side request forgeryEPSS 0.5%CVE-2025-0463MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php unrestricted uploadEPSS 0.4%CVE-2025-8219MEDIUMShanghai Lingdang Information Technology Lingdang CRM HTTP POST Request tabdetail_moduleSave_dxkp.php sql injectionEPSS 0.4%