Haichang OA SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability exists in Haichang OA version 1.0.0, allowing remote attackers to access sensitive information. The vulnerability arises in the 'if' parameter within the 'hcit.project.rte.agents.UploadImages.class' file.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify sensitive information.

Added: Jul 17, 2025, 5:16 PM
Updated: Jul 17, 2025, 5:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.