Dahua Smart Cloud Gateway Registration Platform SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Dahua Smart Cloud Gateway Registration Management Platform. This vulnerability arises in the '/index.php/User/doLogin' endpoint, where the application does not adequately sanitize user input in the username parameter. As a result, unauthenticated attackers can inject arbitrary SQL statements, potentially leading to the disclosure of sensitive database information.

Impact

Exploitation of this vulnerability allows for SQL injection, where attackers can manipulate database queries to extract, modify, or delete data. This could result in unauthorized access to sensitive information or disruption of data integrity.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/index.php/User/doLogin' endpoint with a crafted SQL injection payload in the username parameter. The injected SQL code can be used to exploit the vulnerability, such as by extracting database information or executing arbitrary commands, depending on the database and application configuration.

Remediation

Users are advised to upgrade to the latest version of the Dahua Smart Cloud Gateway Registration Management Platform, which addresses this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.