CNNVD-202510-863 Information

CNNVD ID

CNNVD-202510-863

CVE-2025-11315

  • CNNVD Published: 2025-10-06

Description (Chinese)

Tipray Data Leakage Prevention System是中国天锐(Tipray)公司的一款数据防泄密系统。 Tipray Data Leakage Prevention System 1.0版本存在SQL注入漏洞,该漏洞源于对文件findUserPage.do中参数sort的错误操作,可能导致SQL注入攻击。

Description (English)

Tipray Data Leakage Protection System is a data-discretion protection system of the Chinese company Tipray. There is an SQL injection loophole in version 1.0 of Tipray Data Leakage System, which stems from an error in the sort of the parameter in the FindUse.do file, which could lead to an SQL injection attack.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

天锐

Published

2025-10-06

Last Modified

2026-02-24

References

https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-7.md https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-7.md#3-proof-of-concept-poc https://vuldb.com/?ctiid.327196 https://vuldb.com/?id.327196 https://vuldb.com/?submit.663494

Share on: