CVE-2025-60266
09.10.2025, 17:16
In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection vulnerability.
| Vendor | Product | Version |
|---|---|---|
| bestfeng | xckk | 9.6 |
𝑥
= Vulnerable software versions