github.comexploit
https://github.com/yanbeiii/Proof-of-Concept/blob/main/lylme-sqli.md CVE-2025-4543
MEDIUM
LyLme Spage ajax_link.php sql injection
Record summary
CVE-2025-4543 has a selected CVSS score of 6.9 (medium).
Description
A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the file lylme_spage/blob/master/admin/ajax_link.php. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SpageBrowse LyLme / Spage | CVE List | 2.1 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4543 VDB-308289 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.308289 VDB-308289 | LyLme Spage ajax_link.php sql injectionvdb entryTechnical description
https://vuldb.com/?id.308289 Submit #567290 | LyLme lylme_spage 2.1 SQL InjectionThird-party advisory
https://vuldb.com/?submit.567290