SQL Injection Vulnerability in HuangDou UTCMS V9
CVE-2025-56407

8.8HIGH

Key Information:

Vendor

HuangDou

Status
Vendor
CVE Published:
10 September 2025

What is CVE-2025-56407?

A severe SQL injection vulnerability exists in HuangDou UTCMS V9, specifically within the RunSql function located in app/modules/ut-data/admin/mysql.php. This flaw allows attackers to manipulate the sql argument, potentially leading to unauthorized access to the database. The vulnerability can be exploited remotely, prompting immediate attention from users and administrators to secure their installations. Prompt remediation is advised to prevent any unauthorized data access or system compromise.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-56407 : SQL Injection Vulnerability in HuangDou UTCMS V9