First published: Wed Feb 19 2025(Updated: )
A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing of the file /wuser/admin.house.collect.php. The manipulation of the argument project_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Baiyi Cloud Asset Management System | <=20250204 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1464 is classified as critical, indicating a high level of risk.
To fix CVE-2025-1464, update the Baiyi Cloud Asset Management System to a version after 20250204.
CVE-2025-1464 is an SQL injection vulnerability affecting the Baiyi Cloud Asset Management System.
CVE-2025-1464 affects the file /wuser/admin.house.collect.php in the Baiyi Cloud Asset Management System.
If CVE-2025-1464 is exploited, it could allow unauthorized access to the database and manipulation of data.