Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Shanghai Lingdang Information Technology
Shanghai Lingdang Information Technology lingdang Crm |
|
Vendors & Products |
Shanghai Lingdang Information Technology
Shanghai Lingdang Information Technology lingdang Crm |
Tue, 09 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unknown function of the file crm/WeiXinApp/dingtalk/index_event.php. The manipulation of the argument corpurl results in server-side request forgery. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Shanghai Lingdang Information Technology Lingdang CRM index_event.php server-side request forgery | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-09T18:39:56.328Z
Reserved: 2025-05-20T13:22:16.157Z
Link: CVE-2025-5005

No data.

Status : Received
Published: 2025-09-09T17:16:15.000
Modified: 2025-09-09T19:15:58.240
Link: CVE-2025-5005

No data.

Updated: 2025-09-09T21:31:15Z