CVE-2025-8219 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7 HTTP POST Request tabdetail_moduleSave_dxkp.php getvaluestring sql injection (EUVD-2025-22807)
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been declared as critical. Impacted is an unknown function of the file /crm/crmapi/erp/tabdetail_moduleSave_dxkp.php of the component HTTP POST Request Handler. Executing manipulation of the argument getvaluestring can lead to sql injection.
This vulnerability is handled as CVE-2025-8219. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+. We strongly advise all customers to upgrade to the current version (v8.6.5.2), which includes this fix and additional security enhancements."