Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32190 | YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges. |
Thu, 30 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yiovo
Yiovo firefly Mall |
|
| CPEs | cpe:2.3:a:yiovo:firefly_mall:*:*:*:*:open_source:*:*:* | |
| Vendors & Products |
Xany
Xany yoshop2.0 |
Yiovo
Yiovo firefly Mall |
Tue, 07 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xany
Xany yoshop2.0 |
|
| CPEs | cpe:2.3:a:xany:yoshop2.0:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Xany
Xany yoshop2.0 |
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yoshop
Yoshop yoshop |
|
| Vendors & Products |
Yoshop
Yoshop yoshop |
Thu, 02 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-02T19:26:40.142Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56162
Updated: 2025-10-02T19:26:32.286Z
Status : Analyzed
Published: 2025-10-02T16:15:35.047
Modified: 2025-10-30T18:33:10.513
Link: CVE-2025-56162
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:39Z
EUVD