CVE-2025-8908 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4 event.php openid sql injection
A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4 and classified as critical. This vulnerability affects unknown code of the file crm/WeiXinApp/yunzhijia/event.php. This manipulation of the argument openid causes sql injection.
This vulnerability is handled as CVE-2025-8908. The attack can be initiated remotely. Additionally, an exploit exists.
The affected component should be upgraded.
The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+."