Metrics
Affected Vendors & Products
Fri, 07 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Title | DedeBIZ spec_add.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-07T16:02:05.050Z
Updated: 2025-11-07T19:25:27.663Z
Reserved: 2025-11-07T10:11:52.864Z
Link: CVE-2025-12861
Updated: 2025-11-07T19:25:18.530Z
Status : Received
Published: 2025-11-07T16:15:38.023
Modified: 2025-11-07T20:15:36.993
Link: CVE-2025-12861
No data.