Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11353 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. |
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geeeeeeeek
Geeeeeeeek dingfanzu |
|
| CPEs | cpe:2.3:a:geeeeeeeek:dingfanzu:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Geeeeeeeek
Geeeeeeeek dingfanzu |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-16T14:22:36.193Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28100
Updated: 2025-04-16T14:22:12.334Z
Status : Analyzed
Published: 2025-04-15T18:15:51.057
Modified: 2025-04-22T17:54:47.210
Link: CVE-2025-28100
No data.
OpenCVE Enrichment
No data.
EUVD