CVE-2025-1535

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 21, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-1535 is a critical vulnerability affecting Baiyi Cloud Asset Management System version 8.142.100.161. An unknown part of the file /wuser/admin.ticket.close.php is vulnerable to sql injection, which can be exploited by manipulating the argument ticket_id. This vulnerability can be exploited remotely and the exploit has been made public. The vendor was notified of this disclosure but did not respond, leaving the system potentially susceptible to attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share