Shanghai Lingdang Information Technology Lingdang CRM SQL Injection Vulnerability

Vulnerability

A critical SQL injection vulnerability has been identified in Shanghai Lingdang Information Technology's Lingdang CRM, affecting versions through 8.6.0.0. The issue arises from the file '/crm/weixinmp/index.php' where the 'searchcontent' argument can be manipulated, allowing for SQL injection attacks to be executed remotely.

Impact

Exploitation of this vulnerability allows for SQL injection, which could lead to unauthorized data access or manipulation in the application's database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.