CNNVD-202508-1481 Information

CNNVD ID

CNNVD-202508-1481

CVE-2025-8934

  • CNNVD Published: 2025-08-14

Description (Chinese)

1000 Projects Sales Management System是1000 Projects开源的一个销售管理系统。 1000 Projects Sales Management System 1.0版本存在代码注入漏洞,该漏洞源于文件/sales.php中参数select2112的错误操作导致跨站脚本攻击。

Description (English)

1,000 Projects Sales Management Systems is a sales management system that is an open source of 1,000 Projects. Version 1.0 of 1000 Projects Sales Management System contains a code-injection loophole, which stems from the error of the parameter Selfact 2112 in file/sales.php, resulting in a cross-site script attack.

Hazard Level

High

Vulnerability Type

代码注入

Affected Vendor

1000 Projects

Published

2025-08-14

Last Modified

2026-02-24

References

https://1000projects.org/ https://github.com/lan041221/cvec/issues/5 https://vuldb.com/?ctiid.319896 https://vuldb.com/?id.319896 https://vuldb.com/?submit.631727

Share on: