PT-2023-14707 · Tencent+1 · Wechat+1

Published

2023-02-21

·

Updated

2025-03-17

·

CVE-2022-45564

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions znfit Home improvement ERP management system versions V42 through V50 20220207
Description The issue allows attackers to execute arbitrary SQL commands via the userCode parameter to the WeChat applet, potentially leading to unauthorized data access or modification.
Recommendations For versions V42 through V50 20220207, consider restricting access to the userCode parameter in the WeChat applet until a patch is available. As a temporary workaround, avoid using the userCode parameter in the affected WeChat applet endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45564

Affected Products

Wechat
Znfit Home Improvement Erp Management System