PT-2025-37051 · Unknown · Huangdou Utcms Version 9
August829
+1
·
Publicado
2025-09-10
·
Atualizado
2025-09-15
·
CVE-2025-56407
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
HuangDou UTCMS version 9
Description:
A critical issue exists in HuangDou UTCMS version 9 related to SQL injection. The vulnerability affects the
RunSql function within the app/modules/ut-data/admin/mysql.php file. Manipulation of the sql argument allows for SQL injection attacks, which can be initiated remotely. The exploit for this issue has been publicly disclosed.Recommendations:
As a temporary workaround, consider restricting access to the
app/modules/ut-data/admin/mysql.php file.
Avoid using the sql parameter in the RunSql function until the issue is resolved.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huangdou Utcms Version 9