Description 禅道是中国易软天创网络科技(Nature Easy Soft Network Technology)公司的一套项目管理软件。其中 dbName 参数过滤不严格,存在SQL注入漏洞。
Related VulnerabilitiesPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-73034: DB-GPT <= 0.8.1 - Arbitrary File WritePoCCVE-2023-25826: OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot InjectionApache IoTDB 认证绕过与远程代码执行漏洞PoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback ExportPoCCVE-2026-6875: ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCEDiscuz! X5.0 /api/db/dbbak.php 权限绕过漏洞(CVE-2026-49952)用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞Grafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)PoCCVE-2026-47670: DbGate - Remote Code Execution via Dynamic Import BypassPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessDbGate存在远程代码执行(CVE-2026-47668)DbGate /runners/start 代码执行漏洞 (CVE-2026-47668)