CVE-2026-3818
Plain English Summary
AI-powered analysis for quick understanding
An attacker can remotely exploit a flaw in Tiandy Easy7 CMS to execute SQL injection attacks, allowing them to manipulate the database and potentially access or alter sensitive information. This vulnerability affects a specific function in the software, and the vendor has not responded to warnings about it.
Technical Description
A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This manipulation of the argument strTBName causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 9, 2026
29 days ago
Last Modified
Mar 10, 2026
28 days ago
Vendor
tiandy
Product
easy7 cms