CVE-2026-37428

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-13 14:17

Updated : 2026-06-17 10:41


NVD link : CVE-2026-37428

Mitre link : CVE-2026-37428

CVE.ORG link : CVE-2026-37428


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')