Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 07 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Title | DedeBIZ freelist_main.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-11-07T20:42:56.659Z
Reserved: 2025-11-07T10:08:02.396Z
Link: CVE-2025-12860
Updated: 2025-11-07T20:42:47.156Z
Status : Received
Published: 2025-11-07T15:15:40.110
Modified: 2025-11-07T21:15:40.267
Link: CVE-2025-12860
No data.
OpenCVE Enrichment
No data.