YunaiV yudao-cloud SQL Injection Vulnerability in Tenant API

Vulnerability

A SQL injection vulnerability has been identified in YunaiV yudao-cloud versions prior to 2026.01. The issue resides in the API endpoint '/admin-api/system/tenant/get-by-website', where the 'website' parameter can be manipulated to execute arbitrary SQL commands. This vulnerability allows for boolean-based blind SQL injection, enabling attackers to interact with the database. The flaw can be exploited remotely without authentication.

Impact

Exploitation of this vulnerability allows for boolean-based blind SQL injection, where an attacker can manipulate SQL queries to extract information from the database or potentially modify database contents.

Reproduction

To reproduce this vulnerability, send a GET request to the '/admin-api/system/tenant/get-by-website' endpoint with a crafted 'website' parameter that includes SQL injection payloads. The injection can be verified by observing the application's response or by using a tool like SQLMap to automate the exploitation.

Added: Mar 30, 2026, 7:19 PM
Updated: Mar 30, 2026, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
4.9
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.