IdeaCMS har 1.7 getList.html Article/Goods Furɗe SQL Injection

CVSS Meta Temp ScoreGarga na exploit ndiyam (≈)CTI Nganji Score
7.0$0-$5k0.12

Gundumabayani

Wuro vulnerability wey an yi classify sey kura an gano shi a cikin IdeaCMS har 1.7. Gaskiya, Article/Goods na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /api/v1.index.article/getList.html na cikin fayil, $software_component na cikin sashi. Ngam manipulation of the argument Furɗe shi SQL Injection. Wannan rauni ana sayar da shi da suna CVE-2025-5569. Ngam yiɗi ka a tuma ndiyam ka internet. Ba exploit ɗin da ake da shi. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a hokkata. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Furɗebayani

Wuro vulnerability wey an yi classify sey kura an gano shi a cikin IdeaCMS har 1.7. Gaskiya, Article/Goods na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /api/v1.index.article/getList.html na cikin fayil, $software_component na cikin sashi. Ngam manipulation of the argument Furɗe shi SQL Injection. CWE shidin ka a yi bayani matsala sai ya kai CWE-89. Gaskiya, laifi an fitar da shi a matsayin ICBVWE. Advisory ɗin ana rabawa don saukewa a gitee.com.

Wannan rauni ana sayar da shi da suna CVE-2025-5569. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal bayani ga. Wannan vulnerability ɗin ba shi da yawa sosai. Ba exploit ɗin da ake da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro.

Á wúro a wondi feere.

Patch ɗin sunan ganowa shine 935aceb4c21338633de6d41e13332f7b9db4fa6a. Bugfix ɗin an shirya shi don saukewa a gitee.com. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a hokkata.

If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Kayanbayani

Sunu

Furɗe

Webseite

CPE 2.3bayani

CPE 2.2bayani

CVSSv4bayani

VulDB Furɗo: 🔒
VulDB Gaskiya: 🔍

CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Furɗo: 🔒

CVSSv3bayani

VulDB Meta Base Score: 7.1
VulDB Meta Temp Score: 7.0

VulDB Ganda Borno: 6.3
VulDB Temp Score: 6.0
VulDB Furɗo: 🔒
VulDB Gaskiya: 🔍

NVD Ganda Borno: 8.8
NVD Furɗo: 🔒

CNA Ganda Borno: 6.3
CNA Furɗo: 🔒

CVSSv2bayani

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
VektarKumpleksitiAuthentisierungKariyandiGaskiyaGashina
furufurufurufurufurufuru
furufurufurufurufurufuru
furufurufurufurufurufuru

VulDB Ganda Borno: 🔒
VulDB Temp Score: 🔒
VulDB Gaskiya: 🔍

Gargajiyabayani

Klasu: SQL Injection
CWE: CWE-89 / CWE-74 / CWE-707
CAPEC: 🔒
ATT&CK: 🔒

Fizikal: Ayi
Gumti: Ayi
Gana: Ee

Gashina: 🔒
Halitta: A wondi feere
Google Hack: 🔒

EPSS Score: 🔒
EPSS Percentile: 🔒

Furɗo farashi: 🔍
Gaskiya farashi ndiyam: 🔒

0-Dayfurufurufurufuru
Lalefurufurufurufuru

Bayani na barazanabayani

Ngam: 🔍
Akteɓe ɓernde: 🔍
Kura APT goruwa masu aiki: 🔍

Kari gamjibayani

Garga: Gargajiya
Halitta: 🔍

0-Day Gana: 🔒

Gargajiya: IdeaCMS 1.8
Kari: 935aceb4c21338633de6d41e13332f7b9db4fa6a

Waktin layibayani

06/03/2025 Advisory ganna fa.
06/03/2025 +0 Hənde VulDB gite be nayi
10/03/2025 +122 Hənde VulDB gite wuro karshe ta gyara

Ngizimbayani

Kayan: gitee.com

Gargaaji: ICBVWE
Halitta: Gaskiya
Tafsirga: 🔒

CVE: CVE-2025-5569 (🔒)
GCVE (CVE): GCVE-0-2025-5569
GCVE (VulDB): GCVE-100-311027
EUVD: 🔒

Gumtibayani

Súgá: 06/03/2025 22:33
Gargadi: 10/03/2025 04:36
Goyarwa: 06/03/2025 22:33 (59), 06/04/2025 09:34 (1), 06/04/2025 11:02 (30), 10/03/2025 04:36 (12)
Gadankam: 🔍
Ngwazarma: johndoe245
Cache ID: 253:E38:103

Súbítbayani

Shingilam

  • Súbít #588372: IdeaCMS IdeaCMS开源商城系统 1.2/1.3/1.4/1.5/1.6/1.7 SQL Injection (nga johndoe245)

Ganaaji

A ga wuroyo kulu. Kàlàmbe: kr + en.

Ngam loga ka, kanyi shidin dum.

Do you want to use VulDB in your project?

Use the official API to access entries easily!