SQL Injection Vulnerability in Lingdang CRM by Shanghai Lingdang Information Technology
CVE-2025-0462

Currently unrated

What is CVE-2025-0462?

A critical SQL injection vulnerability exists in the Lingdang CRM software by Shanghai Lingdang Information Technology, affecting versions up to 8.6.0.0. This issue arises due to improper handling of user-supplied input in the file /crm/weixinmp/index.php, specifically the searchcontent parameter. An attacker can exploit this flaw remotely to manipulate database queries, potentially leading to unauthorized access or data manipulation. Despite early notifications to the vendor regarding this vulnerability, no official response has been recorded.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

.