RULE(RULE ID:338650)

Rule General Information
Release Date: 2025-01-14
Rule Name: 51mis CRM getMyAmbassador API SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: 51mis CRM is an intelligent customer relationship management tool designed for smes. Widely used in finance, education, medical care, IT services, real estate and other industries, to help enterprises achieve customer personalized management needs, enhance enterprise competitiveness. A SQL injection vulnerability exists in the getMyAmbassador interface of Lindon CRM. An unauthenticated remote attacker can use the SQL injection vulnerability to obtain information in the database (such as administrator background password and site user personal information), and even write Trojans to the server with high permission. Obtain the system permission of the server.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.