该漏洞存在于 ERP 系统中,原因是 API 端点对用户提供的输入缺乏充分的验证和参数化处理。未认证的远程攻击者可以通过向该易受攻击的端点提供精心构造的输入来利用此漏洞。 成功利用此漏洞将使攻击者能够对目标系统执行 SQL 注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Manacle Technologies | Multi-tenant ERP System | version | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107102 | 9.3 CRITICAL | Account Takeover Vulnerability in Manacle Technologies ERP System |
| CVE-2026-107104 | 9.3 CRITICAL | Unsafe Deserialization Vulnerability in Manacle Technologies ERP System |
No comments yet