CVE-2025-2217

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 12, 2025
Updated: Mar 25, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-2217 is a critical vulnerability affecting the ProcessRequest function in zzskzy Warehouse Refinement Management System 1.3. The issue arises due to insufficient input validation, which allows an attacker to manipulate the showid argument and execute SQL injection attacks. These attacks can be initiated remotely, making the vulnerability a significant security risk. The exploit for this vulnerability has been publicly disclosed, increasing the potential for malicious use. Despite early notification, the vendor has yet to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share