Impact
A SQL injection flaw exists in Management Platform 6.3.5.4, impacting an unknown function of the /sysAuthStr/querySysAuthStr.do file. By manipulating the argument order, attackers can execute arbitrary SQL statements, which can enable remote access to sensitive data or alteration of database contents. The weakness is classified under CWE‑74 and CWE‑89.
Affected Systems
The affected product is Hanwang e‑Face General Management Platform, version 6.3.5.4. No other versions are listed as vulnerable in the available data.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score of <1% signals a very low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. However, the description confirms that the exploit is publicly available and remotely accessible, which increases its real‑world risk. Potential attackers can reach the vulnerable endpoint over the network and execute the injection without needing local privileges.
OpenCVE Enrichment