CNNVD-202508-3158 Information

CNNVD ID

CNNVD-202508-3158

CVE-2025-34162

  • CNNVD Published: 2025-08-27

Description (Chinese)

Bian Que Feijiu Intelligent Emergency and Quality Control System(扁鹊飞救智能急救与质控系统)是中国扁鹊飞救(Bian Que Feijiu)公司的一款基于大急救与区域协同救治理念的急救管理系统。 Bian Que Feijiu Intelligent Emergency and Quality Control System存在安全漏洞,该漏洞源于GetLyfsByParams端点未清理strOpid参数,可能导致SQL注入攻击。

Description (English)

Bian Que Feijiu Intelligent Agency and Quality Control System is a first aid management system based on the idea of co-regulating first aid with the region. Bian Que Feijiu Intelligent Emergency and Quality Control System has a security loophole, which originates from the failure of the GetLyfs ByParams endpoint to clean up stropid parameters, which could lead to an SQL injection attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

扁鹊飞救

Published

2025-08-27

Last Modified

2026-02-24

References

https://www.vulncheck.com/advisories/bian-que-feiju-intelligent-emergency-and-quality-control-system-sqli https://github.com/wooluo/nuclei-templates-2025hw/blob/main/bianque-medical-sql-injection.yaml https://cn-sec.com/archives/4160402.html http://www.ivtbq.com/ https://nvd.nist.gov/vuln/detail/CVE-2025-34162

Share on: