Fujian Smart Integrated Management Platform SQL Injection Vulnerability in XAccessPermissionPlus.ashx

Vulnerability

A time-based blind SQL injection vulnerability has been identified in the Fujian Smart Integrated Management Platform System, specifically in version 7.5 and prior. The issue arises in the file '/Module/CRXT/Controller/XAccessPermissionPlus.ashx', where the 'DeviceIDS' parameter is not properly sanitized before being used in SQL queries. This vulnerability allows remote attackers to inject malicious SQL commands that can be executed in the database, potentially leading to unauthorized access to sensitive information, data manipulation, or system compromise. The vulnerability does not require authentication, making it accessible to any attacker.

Impact

Exploitation of this vulnerability allows for unauthorized execution of SQL commands, with the potential to access, modify, or delete database information. Additionally, the vulnerability could be exploited to cause a denial-of-service by introducing delays in database response times. The vulnerability is widespread, with over 300 instances of the affected platform identified.

Reproduction

To reproduce this vulnerability, send a POST request to '/Module/CRXT/Controller/XAccessPermissionPlus.ashx' with the 'DeviceIDS' parameter manipulated to include a SQL injection payload. The injection can be verified by measuring the response time; a delay of several seconds indicates successful exploitation.

Added: Feb 20, 2026, 2:31 AM
Updated: Feb 20, 2026, 2:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
3.2
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.