CVE-2025-12859: DedeBIZ templets_one_edit.php sql injection
A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templetsoneedit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12859?
CVE-2025-12859 has been categorized as a high-severity vulnerability due to its potential for remote exploitation via SQL injection.
What software versions are affected by CVE-2025-12859?
CVE-2025-12859 affects DedeBIZ versions up to and including 6.3.2.
How do I fix CVE-2025-12859?
To fix CVE-2025-12859, you should update DedeBIZ to the latest version that addresses this SQL injection vulnerability.
What is the nature of the vulnerability in CVE-2025-12859?
CVE-2025-12859 is an SQL injection vulnerability found in the /admin/templets_one_edit.php file, allowing attackers to manipulate arguments.
Can CVE-2025-12859 be exploited remotely?
Yes, CVE-2025-12859 can be exploited remotely, making it a significant security concern.