CVE-2025-1797
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Mar 1, 2025
Updated: Mar 3, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-1797 is a critical vulnerability affecting the Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to version 20250217. This issue lies in an unidentified functionality of the file /wuser/anyUserBoundHouse.php, which can be exploited through sql injection by manipulating the argument huid. An attacker can leverage this vulnerability to launch remote attacks and gain unauthorized access to the system, with the exploit having already been disclosed to the public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.