Landray EIS 2001 through 2006 contains a SQL injection caused by unsanitized input in Message/fi_message_receiver.aspx?replyid=, letting attackers execute arbitrary SQL commands, exploit requires crafted input.
id: CVE-2025-22214
info:
name: Landray EIS SQL注入漏洞
author: Ark
severity: critical
descripti
...