First published: Tue Jan 14 2025(Updated: )
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minipro_const_type=1&related_module=Singin. The manipulation of the argument name leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lingdang CRM by Shanghai Lingdang Information Technology | <=8.6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0463 has been classified as critical due to its potential impact on the affected software.
To fix CVE-2025-0463, it is recommended to update Lingdang CRM to a version beyond 8.6.0.0.
CVE-2025-0463 affects Lingdang CRM by Shanghai Lingdang Information Technology up to version 8.6.0.0.
CVE-2025-0463 affects an unknown function in the file /crm/weixinmp/index.php related to user actions.
Yes, the critical nature of CVE-2025-0463 suggests that there is a significant risk of data exposure.