Unknown · Zzskzy Warehouse Refinement Management System · CVE-2025-2217
Name of the Vulnerable Software and Affected Versions:
zzskzy Warehouse Refinement Management System version 1.3
Description:
A critical issue was found in the system, affecting the `ProcessRequest` function of the file `/getAdyData.ashx`. The manipulation of the `showid` argument leads to SQL injection. This issue can be exploited remotely. The details of the issue have been publicly disclosed.
Recommendations:
For zzskzy Warehouse Refinement Management System version 1.3, as a temporary workaround, consider restricting access to the `/getAdyData.ashx` file or disabling the `ProcessRequest` function until a patch is available. Avoid using the `showid` argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.