PT-2026-3366 · Unknown · Risesoft-Y9 Digital-Infrastructure
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
risesoft-y9 Digital-Infrastructure versions up to 9.6.7
Description
A flaw exists in risesoft-y9 Digital-Infrastructure up to version 9.6.7. The issue affects an unknown function within the file
source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the REST Authenticate Endpoint component. A manipulation can lead to SQL injection, and the attack can be launched remotely. The exploit has been published. The project was informed of the issue but has not responded.Recommendations
Update risesoft-y9 Digital-Infrastructure to a version later than 9.6.7.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Risesoft-Y9 Digital-Infrastructure