Baiyi Cloud Asset Management System SQL Injection Vulnerability in admin.ticket.close.php

Vulnerability

A critical SQL injection vulnerability has been identified in Baiyi Cloud Asset Management System version 8.142.100.161. The issue resides in the file /wuser/admin.ticket.close.php, where the ticket_id parameter can be manipulated to execute malicious SQL commands. This vulnerability can be exploited remotely without authentication, allowing attackers to bypass security measures and access sensitive information such as database names, table structures, and user data. The vulnerability could also be used to escalate privileges and disrupt service by corrupting database integrity.

Impact

Exploitation of this vulnerability could lead to unauthorized database access, allowing attackers to exfiltrate sensitive data, manipulate database records, and potentially escalate privileges to gain full control over the server. Such actions could disrupt application availability and integrity, causing downtime and data corruption.

Reproduction

To reproduce this vulnerability, send a request to the /wuser/admin.ticket.close.php endpoint with a crafted ticket_id parameter that includes SQL injection payloads. The injection can be time-based, using SQL functions like SLEEP() to create delays that indicate successful exploitation. This vulnerability can be found on multiple asset instances.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.