References https://blog.csdn.net/weixin_65311462/article/details/142532387 https://nvd.nist.gov/vuln/detail/CVE-2025-8345 https://github.com/advisories/GHSA-4692-rqch-8m26 https://www.cvedetails.com/cve/CVE-2025-8345/ https://radar.offseq.com/threat/cve-2025-8345-sql-injection-in-shanghai-lingdang-i-0c52a08d https://dbugs.ptsecurity.com/vulnerability/PT-2025-31468 https://cn-sec.com/archives/3184395.html https://wiki.shikangsi.com/post/share/4d05b8c3-5464-48f3-bb14-a852b6e70abc
Related VulnerabilitiesPoChuatiandongli-oa-downloadfortrace-fileread: 灵当CRM Playforrecord.php 任意文件读取漏洞PoClingdang-crm-playforrecord-fileread: 灵当CRM Playforrecord.php 任意文件读取漏洞灵当CRM yunzhijiaApi.php 存在SQL注入漏洞(CVE-2025-8345)灵当CRM /crm/WeiXinApp/marketing/index.php 服务器端请求伪造漏洞灵当CRM /crm/wechatSession/index.php 文件上传漏洞灵当 CRM /crm/WeiXinApp/CallRecordLog/getLogInfo.php 文件上传漏洞灵当CRM /crm/modules/XlsImportNew/documentEntry/XlsFileUpload.php 文件上传漏洞灵当CRMV8.6.3.3.11 getLogInfo.php文件上传灵当CRMV8.6.3.3.11 uploadify.php文件上传