Impact
A remote attacker can exploit a classic SQL injection flaw in the /user/getUserLogin endpoint of Shenzhou Shihan Video Conference System version 1.0. By inserting malicious SQL statements, the attacker can bypass authentication and gain the ability to execute arbitrary commands on the server, compromising confidentiality, integrity, and availability of the system. This weakness is identified as CWE‑89.
Affected Systems
The vulnerability is confirmed for Shenzhou Shihan Video Conference System version 1.0. No additional affected versions are disclosed, so the reach of the flaw is limited to deployments of this specific version. Exact vendor details beyond the product name are not provided, so administrators should verify if their installations match this release.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical. The EPSS score of <1% suggests that exploitation in the wild is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw allows remote code execution when the /user/getUserLogin endpoint is exposed to the internet, making the attack vector likely remote over HTTP(S).
OpenCVE Enrichment