关键漏洞信息 TVN ID TVN-202508006 CVE ID CVE-2025-8857 CVE-2025-8858 CVSS CVE-2025-8857: 9.8 (Critical) CVE-2025-8858: 7.5 (High) 受影响产品 Clinic Image System version 2.4.23.2131 and earlier, except for version 1.5.x.x and 2.0.x.x. 描述 CVE-2025-8857: Hard-coded Credentials - Unauthenticated remote attackers can log into the system using administrator credentials embedded in the source code. CVE-2025-8858: SQL Injection - Unauthenticated remote attackers can inject arbitrary SQL commands to read database contents. 解决方案 Update to version after 2.4.23.2131 致谢 Sam Huang (CHT Security) 公布日期 2025-08-29 链接 1. CVE-2025-8857 2. https://www.chtsecurity.com/news/276d7867-dfb1-4a91-bc34-97b0f6a117a3 3. CVE-2025-8858