CVE-2025-57529
CRITICALYouDataSum CPAS Audit Management System <=4.9 - SQL Injection via /cpasList/findArchiveReportByDah
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-57529. PoCs published by songqb-xx.
AI-analyzed exploit summary The repository provides a working PoC for CVE-2025-57529, demonstrating an SQL injection vulnerability in CPAS audit management information system. The vulnerability arises from unsanitized user input in the 'dah' parameter, allowing arbitrary SQL execution.
Description
YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access
Exploits (1)
The repository provides a working PoC for CVE-2025-57529, demonstrating an SQL injection vulnerability in CPAS audit management information system. The vulnerability arises from unsanitized user input in the 'dah' parameter, allowing arbitrary SQL execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H