CVE-2025-11309 - CVE House
Back to Database
Status published Medium CVE-2025-11309

Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 findDeptPage.do doFilter sql injection

Vulnerability Description

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Impacted is the function doFilter of the file findDeptPage.do. Performing manipulation of the argument sort results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11309

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • nu11 (VulDB User)

Affected Vendor

Tipray 厦门天锐科技股份有限公司

View all reports →

Affected Software

Data Leakage Prevention System 天锐数据泄露防护系统
Vulnerable Versions:
1.0

Timeline

Official Publish: October 5th, 2025
Last Modified: October 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

Weaknesses (CWE)