CVE-2025-0462 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 searchcontent sql injection
A vulnerability described as critical has been identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. Affected by this vulnerability is an unknown functionality of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minipro_const_type=1. Executing manipulation of the argument searchcontent can lead to sql injection.
This vulnerability appears as CVE-2025-0462. The attack may be performed from a remote location. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.