First published: Mon Mar 03 2025(Updated: )
A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.java. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mini-Tmall | <=20250211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1843 is classified as a critical vulnerability.
To fix CVE-2025-1843, update Mini-Tmall to a version later than 20250211.
CVE-2025-1843 is an SQL injection vulnerability affecting the select function in the ProductMapper.java file.
Yes, the attack exploiting CVE-2025-1843 can be initiated remotely.
CVE-2025-1843 affects Mini-Tmall versions up to and including 20250211.