PT-2025-34567 · Unknown · Bjskzy Zhiyou Erp

Nu11

·

Published

2025-08-24

·

Updated

2025-09-12

·

CVE-2025-9391

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Bjskzy Zhiyou ERP versions prior to 11.1
Description: A weakness has been identified in Bjskzy Zhiyou ERP that allows for remote SQL injection. The issue is related to the manipulation of the sql argument within the getFieldValue function of the com.artery.workflow.ServiceImpl component. The exploit has been made publicly available.
Recommendations: Update Bjskzy Zhiyou ERP to version 11.1 or later. As a temporary workaround, consider restricting access to the getFieldValue function within the com.artery.workflow.ServiceImpl component until a patch is available.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9391

Affected Products

Bjskzy Zhiyou Erp