CNNVD-202511-2988 Information

CNNVD ID

CNNVD-202511-2988

CVE-2025-13770

  • CNNVD Published: 2025-11-28

Description (Chinese)

Uniong WebITR是中国凯发(Uniong)公司的一款在线考勤系统。 Uniong WebITR存在SQL注入漏洞,该漏洞源于SQL注入,允许远程攻击者注入任意SQL命令读取数据库内容。

Description (English)

Uniong WebITR is an online attendance system of Uniong China. Uniong WebITr has a leak in SQL, which originates from SQL injection, allowing remote assailants to inject any SQL command into the database.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

凯发

Published

2025-11-28

Last Modified

2026-02-24

References

https://www.twcert.org.tw/en/cp-139-10539-21f45-2.html https://www.twcert.org.tw/tw/cp-132-10538-6a26d-1.html https://access.redhat.com/security/cve/cve-2025-13770

Patch

https://www.uniong.com.tw/public/index/

Share on: