Junglewise Threat Intelligence

CVE-2025-55849: WeiPHP SQL injection in SucaiController cancelTemplate

CVE-2025-55849 · Severity: high · CVSS 8.4 · Published 2025-09-08

Executive brief

WeiPHP, a platform used for managing WeChat-based applications, contains a security flaw that could allow an attacker to access or modify its underlying database. By sending specially crafted web requests, an unauthorized user could potentially steal sensitive customer data or disrupt the service's operations. This issue affects version 5.0 and all earlier versions of the software.

Technical details

A SQL injection vulnerability exists in WeiPHP versions 5.0 and prior within the `cancelTemplate` method of the `SucaiController.class.php` file. The vulnerability is caused by improper neutralization of the `uid` parameter, which is used in a database query without sufficient sanitization. An attacker can exploit this by sending a crafted HTTP GET request to the `/admin/Sucai/cancelTemplate` endpoint, using techniques such as error-based injection (e.g., `updatexml`) to extract data or modify database records. While the CVSS vector provided by CISA-ADP indicates a local attack vector, the nature of the component and the provided proof-of-concept suggest it is reachable via network requests.

Affected products

  • Shenzhen Dream Cloud Technology Co., Ltd WeiPHP <= 5.0

Timeline

  • 2025-09-06: disclosed: Vulnerability reported on Gitee by Zyun4
  • 2025-09-08: advisory: CVE-2025-55849 published by NVD

References