References https://www.ddpoc.com/DVB-2025-9075.html https://mrxn.net/jswz/baiyishequ-adminx-make-project_id-sqli.html https://www.cnvd.org.cn/flaw/show/CNVD-2025-03911 https://avd.aliyun.com/detail?id=AVD-2025-1783129 https://github.com/adysec/POC/blob/main/wpoc/%E8%B5%84%E7%AE%A1%E4%BA%91/%E7%99%BE%E6%98%93%E4%BA%91%E8%B5%84%E4%BA%A7%E7%AE%A1%E7%90%86%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9Fufile.api.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/LeouMaster/p/18509643 https://cn-sec.com/archives/4227144.html https://www.gm7.org/archives/100046 https://avd.aliyun.com/detail?id=AVD-2024-1767619
Related Vulnerabilities英特內|DreamMaker - 存在2個漏洞Netmaker /api/dns 未授权访问漏洞(CVE-2023-32077)英特內|DreamMaker - 存在5個漏洞short-video-maker /api/tmp 文件读取漏洞(CVE-2026-8115)PoCCVE-2022-1453: RSVPMaker <= 9.2.5 - SQL InjectionPoCCVE-2023-6970: WP Recipe Maker <= 9.1.0 - Reflected XSS via Referer HeaderPoCwp-popup-maker-fpd: Popup Maker - Full Path DisclosurePoCmakefile-exposure: Makefile - ExposurePHPJABBERS Restaurant Menu Maker Project 代码注入漏洞PoCCVE-2019-17574: Popup-Maker < 1.8.12 - Broken AuthenticationPoCCVE-2019-8982: Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request ForgeryPoCCVE-2022-0747: Infographic Maker iList < 4.3.8 - SQL Injection