Impact
A flaw in the GetStoredClassByFilter function of Shandong Hoteam PDM Product Data Management System allows an attacker to inject arbitrary SQL statements through the FilterString parameter. The injection can lead to unauthorized data disclosure, modification, or denial of service against the database used by the application, consistent with CWE‑74 and CWE‑89 weaknesses.
Affected Systems
The vulnerability affects versions up to 8.3.10 of the Shandong Hoteam PDM Product Data Management System. The attack vector is the /Base/BaseService.asmx/DataService endpoint, where the FilterString argument is passed unchecked.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, but it has been publicly disclosed and can be exploited remotely via standard HTTP requests to the DataService service. Attackers do not need authentication, making the risk significant for exposed instances.
OpenCVE Enrichment