What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 沈唁 OSS Aliyun.This issue affects OSS Aliyun: from n/a through 1.4.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 沈唁 OSS Aliyun.This issue affects OSS Aliyun: from n/a through 1.4.10.
Explanation of Vulnerability in Simple Terms
OSS Aliyun versions up to 1.4.10 contain a SQL injection vulnerability in a high-privilege context. An authenticated administrator can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive database records. The vulnerability affects the broader system scope and may impact availability. A patch version is not yet publicly documented.
What an attacker can do
Read sensitive database records or degrade system availability via SQL injection.
Potential impact on your site
An admin account compromise could expose your database contents or cause service disruption.
Conditions required to exploit
Attacker must have high-level administrative privileges on the affected OSS Aliyun installation.
Key dates
External resources
Related vulnerabilities