CNNVD-202510-3551 Information

CNNVD ID

CNNVD-202510-3551

CVE-2025-12289

  • CNNVD Published: 2025-10-27

Description (Chinese)

Suishang Enterprise-Level B2B2C Multi-User Mall System是中国随商(Suishang)公司的一个电商系统软件。 Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0版本存在安全漏洞,该漏洞源于对文件/Point/index/activity_state/1/category_id/1001中参数category_id的错误操作,可能导致跨站脚本攻击。

Description (English)

Suishang Enterprise-Level B2B2C Multi-User Mall System is an electrical system software for Sushang. There is a security loophole in version 1.0 of Suishang Enterprise-Level B2B2C Multi-User Mall System, which stems from an error in the use of the parameter Category id in document/Point/index/Act state/1/category id/1001, which may result in a cross-script attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

随商

Published

2025-10-27

Last Modified

2026-02-24

References

https://github.com/1276486/CVE/issues/19 https://vuldb.com/?ctiid.329957 https://vuldb.com/?id.329957 https://vuldb.com/?submit.675435

Share on: