在 TMT Machine Industry and Trade Ltd. Co. 的 Talassoft 工业管理软件中,由于 SQL 命令中特殊字符未正确中和(即 SQL 注入漏洞),允许攻击者执行 SQL 注入攻击。 该问题影响 Talassoft 工业管理软件:从 V.4 到 V.16 之前(不含 V.16)的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | V.4 ~ V.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18931 | 9.1 CRITICAL | Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-18771 | 7.5 HIGH | Missing Authentication for Critical Function in TMT Machine's Talassoft Industrial Managem |
| CVE-2026-18780 | 7.1 HIGH | CSRF in TMT Machine's Talassoft Industrial Management Software |
No comments yet