TMT Machine Industry and Trade Ltd. Co. 的 Talassoft 工业管理软件中存在跨站请求伪造(CSRF)漏洞。 该漏洞允许攻击者通过跨站请求伪造机制发起攻击。 此问题影响 Talassoft 工业管理软件:从 V.4 至 V.16 之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | V.4 ~ V.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18931 | 9.1 CRITICAL | Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-18630 | 8.8 HIGH | SQL Injection in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-18771 | 7.5 HIGH | Missing Authentication for Critical Function in TMT Machine's Talassoft Industrial Managem |
No comments yet