CNNVD-202508-1482 Information

CNNVD ID

CNNVD-202508-1482

CVE-2025-8935

  • CNNVD Published: 2025-08-14

Description (Chinese)

1000 Projects Sales Management System是1000 Projects开源的一个销售管理系统。 1000 Projects Sales Management System 1.0版本存在注入漏洞,该漏洞源于文件/superstore/custcmp.php中参数Username的错误操作导致SQL注入。

Description (English)

1,000 Projects Sales Management Systems is a sales management system that is an open source of 1,000 Projects. There is an injection loophole in version 1.0 of 1,000 Projects Sales Management System, which results from the error of Username, the parameter in the file/support/cutcmp.php.

Hazard Level

Medium

Vulnerability Type

注入

Affected Vendor

1000 Projects

Published

2025-08-14

Last Modified

2026-02-24

References

https://1000projects.org/ https://github.com/lan041221/cvec/issues/6 https://vuldb.com/?ctiid.319897 https://vuldb.com/?id.319897 https://vuldb.com/?submit.631729

Share on: