0.000
EPSS

CVE-2025-28100

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00077 | KEV: Not Included
Published: 15/04/2025 Updated: 22/04/2025

Vulnerability Summary

SQL Injection in dingfanzuCMS v.1.0 Enables Arbitrary Code Execution

A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a malicious user to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

geeeeeeeek dingfanzu 1.0