← Volver a CVEs
CVE-2025-5569
MEDIUM6.3
Descripcion
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.8 is able to address this issue. The patch is named 935aceb4c21338633de6d41e13332f7b9db4fa6a. It is recommended to upgrade the affected component.
Detalles CVE
Puntuacion CVSS v3.16.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado6/4/2025
Ultima modificacion10/3/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
ideacms:ideacms
Debilidades (CWE)
CWE-74CWE-89CWE-89
Referencias
https://gitee.com/ideacms/ideacms/issues/ICBVWE(cna@vuldb.com)
https://gitee.com/ideacms/ideacms/releases/tag/v1.8(cna@vuldb.com)
https://vuldb.com/?ctiid.311027(cna@vuldb.com)
https://vuldb.com/?id.311027(cna@vuldb.com)
https://vuldb.com/?submit.588372(cna@vuldb.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.