---
id: CVE-2025-11309
title: >-
  A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage
  Prevention System 天锐数据泄露防护系统 1.0
summary: >-
  A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage
  Prevention System 天锐数据泄露防护系统 1.0. Impacted is the function doFilter of the
  file findDeptPage.do. Performing manipulation of the argument sort results in
  sql injectio…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: tipray
product: data_leakage_prevention_system
affected:
  - data_leakage_prevention_system = 1.0
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11309'
references:
  - url: >-
      https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-1.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-1.md#sql-injection-vulnerability
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327190'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327190'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.663382'
    label: cna@vuldb.com
  - url: >-
      https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-1.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/FightingLzn9/vul/blob/main/%E5%A4%A9%E9%94%90%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4%E7%B3%BB%E7%BB%9F-1.md#sql-injection-vulnerability
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00495
epssPercentile: 0.40554
ingestedAt: '2026-10-09T12:53:28.740Z'
---

## Overview

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Impacted is the function doFilter of the file findDeptPage.do. Performing manipulation of the argument sort results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `data_leakage_prevention_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
