CVE-2025-2831

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 27, 2025
Updated: Apr 11, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-2831 is a newly discovered critical vulnerability affecting the mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694. The vulnerability lies in the getBookList function of the file /admin/bookList?page=1&limit=10. An attacker can manipulate the argument condition to execute SQL injection, which can be initiated remotely. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential attacks. Users are strongly advised to update their systems as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share