Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass
Vulnerability Description
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Tencent APIJSON SQL注入漏洞
Vulnerability Description
Tencent APIJSON是中国Tencent公司的一个自动生成API的接口开发框架。 Tencent APIJSON 8.1.8及之前版本存在SQL注入漏洞,该漏洞源于APIJSONORM库的AbstractSQLConfig.java仅对String形式的@having应用按角色允许列表检查而未对Map形式应用,可能导致未经身份验证的远程攻击者绕过每表访问控制并读取任意数据库表。
CVSS Information
N/A
Vulnerability Type
N/A