CVE-2025-9140 is a high-severity SQL injection vulnerability affecting Shanghai Lingdang Information Technology Lingdang CRM up to version 8.6.4.7, specifically within the /crm/crmapi/erp/tabdetail_moduleSave.php file through manipulation of the getvaluestring argument. With a CVSS score of 8.8, this remotely exploitable flaw allows an authenticated attacker to achieve high confidentiality, integrity, and availability impacts. While not currently in CISA's KEV catalog or widely discussed, a public exploit (EDB-52420) exists, and the vendor has released a patch in version 8.6.5.4, addressing the issue with parameterized queries and input sanitization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.5.4CPE matchmatch criteria | cpe:2.3:a:51mis:lingdang_crm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.