Description
A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file /crm/crmapi/erp/tabdetail_moduleSave.php. The manipulation of the argument getvaluestring leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 8.6.5.4 can resolve this issue. The affected component should be upgraded. The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+."
INFO
Published Date :
2025-08-19T13:32:06.591Z
Last Modified :
2025-08-19T13:42:35.904Z
Source :
VulDB
AFFECTED PRODUCTS
The following products are affected by CVE-2025-9140 vulnerability.
Vendors | Products |
---|---|
Shanghai Lingdang Information Technology |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-9140.