User-Xiangpeng Yaoqishan SQL Injection Vulnerability in MediaInfoService

Vulnerability

A critical SQL injection vulnerability has been identified in the Yaoqishan Video Management System, specifically in the MediaInfoService component. The issue arises in the getMediaLisByFilter function, where the typeId argument is manipulated, allowing for SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been made public.

Impact

Exploitation of this vulnerability allows attackers to perform SQL injection, potentially leading to unauthorized access to sensitive system information or manipulation of the database.

Reproduction

To reproduce this vulnerability, send a request to the getMediaLisByFilter function in the MediaInfoService.java file. Manipulate the typeId argument with a crafted input that exploits the application's SQL query handling, taking advantage of insufficient input sanitization to inject malicious SQL code.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.