SQL Injection Vulnerability in HuangDou UTCMS V9
CVE-2025-56407
8.8HIGH
What is CVE-2025-56407?
A severe SQL injection vulnerability exists in HuangDou UTCMS V9, specifically within the RunSql function located in app/modules/ut-data/admin/mysql.php. This flaw allows attackers to manipulate the sql argument, potentially leading to unauthorized access to the database. The vulnerability can be exploited remotely, prompting immediate attention from users and administrators to secure their installations. Prompt remediation is advised to prevent any unauthorized data access or system compromise.