CVE-2025-1535
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Feb 21, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-1535 is a critical vulnerability affecting Baiyi Cloud Asset Management System version 8.142.100.161. An unknown part of the file /wuser/admin.ticket.close.php is vulnerable to sql injection, which can be exploited by manipulating the argument ticket_id. This vulnerability can be exploited remotely and the exploit has been made public. The vendor was notified of this disclosure but did not respond, leaving the system potentially susceptible to attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share