PT-2025-37051 · Unknown · Huangdou Utcms Version 9

·

CVE-2025-56407

·

Published

2025-09-10

·

Updated

2025-09-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: HuangDou UTCMS version 9
Description: A critical issue exists in HuangDou UTCMS version 9 related to SQL injection. The vulnerability affects the RunSql function within the app/modules/ut-data/admin/mysql.php file. Manipulation of the sql argument allows for SQL injection attacks, which can be initiated remotely. The exploit for this issue has been publicly disclosed.
Recommendations: As a temporary workaround, consider restricting access to the app/modules/ut-data/admin/mysql.php file. Avoid using the sql parameter in the RunSql function until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56407

Affected Products

Huangdou Utcms Version 9