CVE-2025-12927: DedeBIZ archives_add.php sql injection
A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archivesadd.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12927?
CVE-2025-12927 is reported as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-12927?
To fix CVE-2025-12927, upgrade DedeBIZ to version 6.3.3 or later where the vulnerability has been patched.
What versions of DedeBIZ are affected by CVE-2025-12927?
DedeBIZ versions up to and including 6.3.2 are affected by CVE-2025-12927.
Can CVE-2025-12927 be exploited remotely?
Yes, CVE-2025-12927 can be exploited remotely due to its nature as a SQL injection vulnerability.
What file is vulnerable in CVE-2025-12927?
The vulnerable file in CVE-2025-12927 is /admin/archives_add.php.