CVE-2025-57529
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access
Affected (1)
Products: Youdatasum: Cpas Audit Management System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.9 |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.