CNNVD-202508-1489 Information

CNNVD ID

CNNVD-202508-1489

CVE-2025-8936

  • CNNVD Published: 2025-08-14

Description (Chinese)

1000 Projects Sales Management System是1000 Projects开源的一个销售管理系统。 1000 Projects Sales Management System 1.0版本存在注入漏洞,该漏洞源于文件/superstore/dist/dordupdate.php中参数select2的错误操作导致SQL注入。

Description (English)

1,000 Projects Sales Management Systems is a sales management system that is an open source of 1,000 Projects. There is an injection loophole in version 1.0 of 1,000 Projects Sales Management System, which results from an error in the selfact2 parameter in the document/superstore/dist/dordupdate.php.

Hazard Level

Medium

Vulnerability Type

注入

Affected Vendor

1000 Projects

Published

2025-08-14

Last Modified

2026-02-24

References

https://1000projects.org/ https://github.com/lan041221/cvec/issues/7 https://vuldb.com/?ctiid.319898 https://vuldb.com/?id.319898 https://vuldb.com/?submit.631748

Share on: