畅捷通CRM 存在一个未经身份验证的 SQL 注入漏洞,允许远程攻击者通过操控 Web 服务接口中的 GET 参数来执行任意 SQL 查询。由于缺乏输入净化或参数化处理,攻击者可以利用基于 UNION 的注入技术,从底层数据库中提取敏感数据。该漏洞的利用证据最早由 Shadowserver 基金会于 2023 年 10 月 18 日观察到。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Chanjet Information Technology Co., Ltd. | CRM | * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Chanjet Information Technology Co., Ltd. | CRM | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet