User-Xiangpeng Yaoqishan SQL Injection Vulnerability in MediaInfoService
Vulnerability
A critical SQL injection vulnerability has been identified in the Yaoqishan Video Management System, specifically in the MediaInfoService component. The issue arises in the getMediaLisByFilter function, where the typeId argument is manipulated, allowing for SQL injection attacks. This vulnerability can be exploited remotely, and details of the exploit have been made public.
Impact
Exploitation of this vulnerability allows attackers to perform SQL injection, potentially leading to unauthorized access to sensitive system information or manipulation of the database.
Reproduction
To reproduce this vulnerability, send a request to the getMediaLisByFilter function in the MediaInfoService.java file. Manipulate the typeId argument with a crafted input that exploits the application's SQL query handling, taking advantage of insufficient input sanitization to inject malicious SQL code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
