PT-2025-34567 · Unknown · Bjskzy Zhiyou Erp

·

CVE-2025-9391

·

Published

2025-08-24

·

Updated

2025-09-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Bjskzy Zhiyou ERP versions prior to 11.1
Description: A weakness has been identified in Bjskzy Zhiyou ERP that allows for remote SQL injection. The issue is related to the manipulation of the sql argument within the getFieldValue function of the com.artery.workflow.ServiceImpl component. The exploit has been made publicly available.
Recommendations: Update Bjskzy Zhiyou ERP to version 11.1 or later. As a temporary workaround, consider restricting access to the getFieldValue function within the com.artery.workflow.ServiceImpl component until a patch is available.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9391

Affected Products

Bjskzy Zhiyou Erp