First published: Wed Mar 12 2025(Updated: )
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
zzskzy Warehouse Refinement Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2217 is classified as a critical vulnerability.
To fix CVE-2025-2217, ensure that user inputs are properly validated and sanitized to prevent SQL injection.
CVE-2025-2217 affects the zzskzy Warehouse Refinement Management System version 1.3.
CVE-2025-2217 can be exploited through the ProcessRequest function by manipulating the argument showid for SQL injection.
Exploitation of CVE-2025-2217 could allow attackers to execute arbitrary SQL commands on the database.