Impact
An SQL injection flaw exists in Hanwang e-Face General Management Platform version 6.3.5.4, triggered by manipulating the argument order in the /sysAuthStr/querySysAuthStr.do endpoint. This permits an attacker to execute arbitrary SQL commands against the underlying database, potentially exposing confidential data, modifying or deleting records, or further escalating privileges. The vulnerability is categorized as CWE-74 and CWE-89.
Affected Systems
The affected product is Hanwang e-Face General Management Platform version 6.3.5.4. No other versions are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% signals a very low but non-zero chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The publicly available exploit and remote accessibility suggest that a hostile actor could reach the vulnerable endpoint over the network and inject malicious SQL without requiring local privileges, thereby risking data confidentiality, integrity, and availability.
OpenCVE Enrichment