Impact
An input validation flaw in the /dm/dispatch/user/findAll endpoint of Rongzhitong Visual Integrated Command and Dispatch Platform allows a remote attacker to inject arbitrary SQL via the Name parameter. The vulnerability is a classic SQL injection (CWE-74/CWE-89). If exploited, an attacker can read, modify, or delete database contents, potentially compromising sensitive operational data and disrupting service.
Affected Systems
The platform is affected in all releases up to and including 20260617. The vendor is Rongzhitong, and the product is Visual Integrated Command and Dispatch Platform.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, no local privileges required, and published exploits exist. Therefore, organizations using the affected version should treat this as a moderate to high threat, especially if the endpoint is exposed to untrusted networks.
OpenCVE Enrichment