CVE-2025-0461

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 22

Summary

CVE-2025-0461 is a newly disclosed vulnerability affecting Shanghai Lingdang Information Technology's CRM software up to version 8.6.0.0. This issue is classified as problematic due to a path traversal flaw present in the file /crm/weixinmp/index.php. An attacker can manipulate the argument 'pathfile' to gain unauthorized access to sensitive files, making this a remotely exploitable vulnerability. The exploit for this flaw has been disclosed to the public, increasing the risk of potential attacks. Despite early notification, the vendor has yet to provide a response or patch for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share