YouDataSum CPAS Audit Management System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the YouDataSum CPAS Audit Management System, affecting versions through 4.9. The issue arises in the 'findArchiveReportByDah' endpoint, where inadequate input validation allows remote, unauthenticated attackers to execute arbitrary SQL commands. Exploitation of this vulnerability could result in unauthorized access to data.

Impact

Exploitation of this vulnerability could lead to unauthorized data access.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/cpasList/findArchiveReportByDah' endpoint. The 'dah' parameter should be crafted to include SQL injection payloads, such as a condition that manipulates the SQL query execution, for example by using 'AND (SELECT(SLEEP(5)))' to demonstrate the injection.

Added: Feb 3, 2026, 7:00 PM
Updated: Feb 3, 2026, 7:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.