Description
GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw located in the /home/message/rubbish endpoint of GouGuOA v6.0.5 and earlier, triggered through the unsanitized 'keywords' HTTP parameter. An attacker can craft malicious input to manipulate the underlying SQL query, potentially read sensitive data, modify or delete database records, and in some configurations elevate privileges. This represents a confidentiality and integrity breach consistent with CWE‑89.

Affected Systems

The affected product is GouGuOA version 6.0.5 and any earlier releases. Users deploying these versions should immediately verify their installed version; the vulnerability persists until a fixing change is applied to the message handling code.

Risk and Exploitability

Official CVSS or EPSS ratings are not available, and the vulnerability is not listed in CISA's KEV catalog. Despite the lack of formal severity metrics, the presence of a SQL injection vector typically warrants a high severity assessment, especially given the potential for full data disclosure or modification.

Generated by OpenCVE AI on October 5, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GouGuOA to the latest version that resolves the SQL injection in the /home/message/rubbish endpoint.
  • If an upgrade is not immediately possible, restrict access to that endpoint by disabling it or applying firewall rules to limit traffic only to trusted network ranges.
  • As a temporary safeguard, implement strict input validation for the 'keywords' parameter, forbidding SQL control characters and enforcing a whitelist of allowed characters or length constraints.
  • Enable application and database logging on the endpoint and monitor for abnormal query activity.

Generated by OpenCVE AI on October 5, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in GouGuOA /home/message/rubbish via Keywords Parameter
Weaknesses CWE-89

Mon, 05 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T15:28:26.372Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:16.957

Modified: 2026-10-05T16:17:16.957

Link: CVE-2026-88395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T16:30:20Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')