Shanghai Lingdang Information Technology Lingdang CRM Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in Shanghai Lingdang Information Technology's Lingdang CRM, affecting versions through 8.6.0.0. The issue arises in the file '/crm/weixinmp/index.php' when specific query parameters are manipulated. This vulnerability allows for remote exploitation by traversing directories and potentially accessing unauthorized files on the server.

Impact

Exploitation of this vulnerability allows for arbitrary file read, which could lead to exposure of sensitive information or application files.

Reproduction

To reproduce this vulnerability, send a request to '/crm/weixinmp/index.php' with the 'userid', 'module', 'usid', 'action', 'minipro_const_type', 'related_module', and 'pathfile' parameters. Manipulate the 'pathfile' argument to traverse directories and access restricted files.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.6
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.