A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://vuldb.com/?ctiid.310258 | Permissions Required VDB Entry |
https://vuldb.com/?id.310258 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.579069 | Third Party Advisory VDB Entry |
https://wx.mail.qq.com/s?k=oVXdxVkeZQAlUQwVe2 | Third Party Advisory |
Configurations
History
03 Jun 2025, 15:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://vuldb.com/?ctiid.310258 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310258 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.579069 - Third Party Advisory, VDB Entry | |
References | () https://wx.mail.qq.com/s?k=oVXdxVkeZQAlUQwVe2 - Third Party Advisory | |
First Time |
Llisoft
Llisoft mta Maita Training System |
|
CPE | cpe:2.3:a:llisoft:mta_maita_training_system:4.5:*:*:*:*:*:*:* |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 May 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-26 05:15
Updated : 2025-06-03 15:41
NVD link : CVE-2025-5170
Mitre link : CVE-2025-5170
CVE.ORG link : CVE-2025-5170
JSON object : View
Products Affected
llisoft
- mta_maita_training_system