PT-2023-14707 · Tencent+1 · Wechat+1

Publicado

2023-02-21

·

Atualizado

2025-03-17

·

CVE-2022-45564

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions znfit Home improvement ERP management system versions V42 through V50 20220207
Description The issue allows attackers to execute arbitrary SQL commands via the userCode parameter to the WeChat applet, potentially leading to unauthorized data access or modification.
Recommendations For versions V42 through V50 20220207, consider restricting access to the userCode parameter in the WeChat applet until a patch is available. As a temporary workaround, avoid using the userCode parameter in the affected WeChat applet endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-45564

Produtos afetados

Wechat
Znfit Home Improvement Erp Management System