PT-2026-97146 · Iflytek · Astron-Agent
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iFlytek astron-agent versions prior to reward-1575
Description
A SQL injection flaw exists in the
getBotList API endpoint within the console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml file. A remote attacker can exploit this by manipulating the sortDirection argument, allowing for the execution of unauthorized SQL commands.Recommendations
Upgrade to version reward-1575.
As a temporary mitigation, avoid using the
sortDirection argument in the getBotList API endpoint.Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astron-Agent