CVE-2025-7102 Information
Jul 08, 2025
cve
Description
A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown code of the file application/update/controller/Server.php. The manipulation of the argument phone leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Reference
https://note-hxlab.wetolink.com/share/sEjaSsXWRNz1 https://note-hxlab.wetolink.com/share/sEjaSsXWRNz1 https://vuldb.com/?ctiid.315016 https://vuldb.com/?id.315016 https://vuldb.com/?submit.604401
Related CNNVD
CNNVD-202507-641 (Published: 2025-07-07)
Share on: