CVE-2025-57529

CRITICAL

YouDataSum CPAS Audit Management System <=4.9 - SQL Injection via /cpasList/findArchiveReportByDah

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-57529. PoCs published by songqb-xx.

AI-analyzed exploit summary The repository provides a working PoC for CVE-2025-57529, demonstrating an SQL injection vulnerability in CPAS audit management information system. The vulnerability arises from unsanitized user input in the 'dah' parameter, allowing arbitrary SQL execution.

Description

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access

Exploits (1)

nomisec WORKING POC
by songqb-xx · poc
https://github.com/songqb-xx/CVE-2025-57529

The repository provides a working PoC for CVE-2025-57529, demonstrating an SQL injection vulnerability in CPAS audit management information system. The vulnerability arises from unsanitized user input in the 'dah' parameter, allowing arbitrary SQL execution.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: CPAS audit management information system <=v4.9
No auth needed
Prerequisites: Network access to the target system · Vulnerable version of CPAS audit management information system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0056
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
youdatasum/cpas_audit_management_system < 4.9
Published Feb 03, 2026
Tracked Since Feb 18, 2026