CVE-2025-60830

redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redragon-erp:redragon-erp:1.0:*:*:*:*:*:*:*

History

10 Oct 2025, 16:16

Type Values Removed Values Added
CPE cpe:2.3:a:redragon-erp:redragon-erp:1.0:*:*:*:*:*:*:*
First Time Redragon-erp
Redragon-erp redragon-erp
References () https://gist.github.com/ChangeYourWay/3b3d3dd5727272c435f1b1f6c17b7181 - () https://gist.github.com/ChangeYourWay/3b3d3dd5727272c435f1b1f6c17b7181 - Third Party Advisory
References () https://github.com/Yyjccc/document/blob/main/redragon-erp/redragon-erp.md - () https://github.com/Yyjccc/document/blob/main/redragon-erp/redragon-erp.md - Exploit

08 Oct 2025, 16:15

Type Values Removed Values Added
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

08 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-08 14:15

Updated : 2025-10-10 16:16


NVD link : CVE-2025-60830

Mitre link : CVE-2025-60830

CVE.ORG link : CVE-2025-60830


JSON object : View

Products Affected

redragon-erp

  • redragon-erp
CWE
CWE-502

Deserialization of Untrusted Data