CVE-2025-1535
HIGHBaiyi Cloud Asset Management System <8.142.100.161 - SQL Injection
Title source: llmDescription
A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploits (1)
github
WORKING POC
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/BaiYiYun_CVE-2025-1535_SQL_Injection.py
References (4)
Scores
CVSS v3
7.3
EPSS
0.0010
EPSS Percentile
27.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
Baiyi/Cloud Asset Management System
8.142.100.161
Published
Feb 21, 2025
Tracked Since
Feb 18, 2026