Home

Description

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access

PUBLISHED Reserved 2025-08-17 | Published 2026-02-03 | Updated 2026-02-04 | Assigner mitre

References

github.com/songqb-xx/CPAS-bug

github.com/songqb-xx/CVE-2025-57529/blob/main/README.md

cve.org (CVE-2025-57529)

nvd.nist.gov (CVE-2025-57529)

Download JSON