Lingdang CRM(灵当CRM)是中国灵当(Lingdang)公司的一个客户关系管理系统。 Lingdang CRM 8.6.4.3及之前版本存在路径遍历漏洞,该漏洞源于文件/crm/data/pdf.php的参数url会导致路径遍历。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 上海灵当信息科技有限公司 | Lingdang CRM | 8.6.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-11122 | 6.3 MEDIUM | 上海灵当信息科技有限公司 Lingdang CRM index.php unrestricted upload |
| CVE-2024-11121 | 6.3 MEDIUM | 上海灵当信息科技有限公司 Lingdang CRM index.php sql injection |
No comments yet