CVE-2025-0462

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-0462 is a newly disclosed critical vulnerability affecting Shanghai Lingdang Information Technology's CRM software up to version 8.6.0.0. The issue lies in the processing of the file /crm/weixinmp/index.php and involves manipulation of the argument searchcontent. This vulnerability leads to SQL injection, allowing remote attackers to exploit it. The vendor has been notified but has yet to respond, making the exploit publicly available and potentially dangerous.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share