SQL Injection Vulnerability in Chanjet TPlus by Chanjet
CVE-2025-14190
Key Information:
Badges
What is CVE-2025-14190?
A critical flaw has been identified in Chanjet TPlus, affecting versions up to 20251121. This vulnerability arises from an insecure implementation in the file handler at /tplus/ajaxpro/Ufida.T.SM.UIP.MultiCompanySettingController,Ufida.T.SM.UIP.ashx?method=Load, where the argument 'currentAccId' can be manipulated, potentially enabling remote attackers to execute arbitrary SQL commands. The exploit has been publicly disclosed, raising significant security risks for users of affected versions. Despite early notification, the vendor has not provided any response regarding this issue.
Affected Version(s)
TPlus 20251121
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
