qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-13 14:17
Updated : 2026-06-17 10:41
NVD link : CVE-2026-37428
Mitre link : CVE-2026-37428
CVE.ORG link : CVE-2026-37428
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
