SQL Injection Vulnerability in HuangDou UTCMS V9
CVE-2025-56407
8.8HIGH
What is CVE-2025-56407?
A severe SQL injection vulnerability exists in HuangDou UTCMS V9, specifically within the RunSql function located in app/modules/ut-data/admin/mysql.php. This flaw allows attackers to manipulate the sql argument, potentially leading to unauthorized access to the database. The vulnerability can be exploited remotely, prompting immediate attention from users and administrators to secure their installations. Prompt remediation is advised to prevent any unauthorized data access or system compromise.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
