OSV 1.4.0 · unreviewed · 修改于 2026-08-28 02:32
发布时间
2026-08-27 08:30
GitHub 审查时间
—
NVD 发布时间
2026-08-27 07:17
源文件
advisories/unreviewed/2026/08/GHSA-w6x9-86mp-c7cf/GHSA-w6x9-86mp-c7cf.json
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
该公告没有提供结构化的受影响软件包信息。