Impact
The vulnerability is a SQL injection flaw located in the Tiandy Easy7 Integrated Management Platform 7.17.0 endpoint /rest/devStatus/queryResources. An attacker can manipulate the "areaId" parameter to inject arbitrary SQL statements against the backend database. The flaw is classified as CWE‑74 and CWE‑89, and if exploited it could allow unauthorized database queries or commands, potentially compromising confidentiality, integrity, or availability of the system’s data.
Affected Systems
The affected system is the Tiandy Easy7 Integrated Management Platform version 7.17.0. No additional product versions are listed in the provided information; the vulnerability is tied specifically to the unknown function of the /rest/devStatus/queryResources endpoint in this version.
Risk and Exploitability
The CVSS base score is 6.9, indicating a medium level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be initiated remotely by sending a crafted HTTP request to the vulnerable endpoint, and a public exploit has been released. Attackers can remotely access the target over the network to exploit the injection, bypass authentication or obtain sensitive data from the database.
OpenCVE Enrichment