NA
CVSSv3

CVE-2025-28100

CVSSv4: NA | CVSSv3: NA | CVSSv2: NA | VMScore: NA | EPSS: 0.00062 | KEV: Not Included
Published: 15/04/2025 Updated: 15/04/2025

Vulnerability Summary

SQL Injection in dingfanzuCMS v.1.0 Enables Arbitrary Code Execution

A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a malicious user to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.