Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-56450

EPSS 0.11% · P28
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-56450

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this by sending a specially crafted POST request, resulting in the execution of arbitrary SQL queries. The backend fails to sanitize the user input, allowing enumeration of database schemas, table names, and potentially leading to full database compromise.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Spacecom Log2Space Subscriber Management Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Spacecom Log2Space Subscriber Management Software是印度Spacecom公司的一个订阅用户管理软件。 Spacecom Log2Space Subscriber Management Software 1.1版本存在安全漏洞,该漏洞源于未对/l2s/api/selfcareLeadHistory端点中的lead_id参数进行验证和清理,可能导致SQL注入攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-56450

#POC DescriptionSource LinkShenlong Link
1Unauthenticated SQL Injection in Log2Space Subscriber Management Softwarehttps://github.com/apboss123/CVE-2025-56450POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-56450

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-10-21 · 27 CVEs total

CVE-2025-605078.9 HIGHMoodle GeniAI plugin 安全漏洞
CVE-2020-368555.3 MEDIUMDCMTK dcmqrscp parseQuota stack-based overflow
CVE-2022-49813.3 LOWDCMTK dcmqrscp dcmqrcnf.cc readPeerList null pointer dereference
CVE-2025-52079D-Link DIR-820L 安全漏洞
CVE-2025-61457sharp 安全漏洞
CVE-2025-56802Reolink desktop application 安全漏洞
CVE-2025-56799Reolink desktop application 安全漏洞
CVE-2025-56801Reolink desktop application 安全漏洞
CVE-2025-56800Reolink desktop application 安全漏洞
CVE-2025-61255PHPGurukul Bank Locker Management System 安全漏洞
CVE-2025-60427Libretime 安全漏洞
CVE-2025-60790ProcessWire 安全漏洞
CVE-2025-60772NETLINK HG322G 安全漏洞
CVE-2025-60506Moodle PDF Annotator plugin 安全漏洞
CVE-2025-60511Moodle OpenAI Chat Block plugin 安全漏洞
CVE-2025-60500QDocs Smart School Management System 安全漏洞
CVE-2025-60280Bang Resto 安全漏洞
CVE-2025-61220MySecondLine 安全漏洞
CVE-2025-61181DaiCuo CMS 安全漏洞
CVE-2025-61194DaiCuo CMS 安全漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-56450

No comments yet


Leave a comment