PT-2025-30082 · Beijing Shenzhou Shihan Technology · Multimedia Integrated Business Display System

Qiantx

·

Published

2025-07-18

·

Updated

2025-07-19

·

CVE-2025-7798

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System versions up to 8.2
Description A critical vulnerability exists in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System. The vulnerability is due to SQL injection in the /admin/system/structure/getdirectorydata/web/baseinfo/companyManage file. Manipulation of the Struccture ID argument allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations Versions prior to 8.3: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-7798

Affected Products

Multimedia Integrated Business Display System