CVE-2025-12860: DedeBIZ freelist_main.php sql injection
A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelistmain.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12860?
CVE-2025-12860 is classified as a high severity vulnerability due to the potential for remote SQL injection.
How do I fix CVE-2025-12860?
To fix CVE-2025-12860, update DedeBIZ to version 6.3.3 or later where this vulnerability is addressed.
What type of vulnerability is CVE-2025-12860?
CVE-2025-12860 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2025-12860 be exploited remotely?
Yes, CVE-2025-12860 can be exploited remotely by an attacker with knowledge of the vulnerable argument.
Which software versions are affected by CVE-2025-12860?
CVE-2025-12860 affects DedeBIZ versions up to and including 6.3.2.