Showing 1 vulnerability on this page for St. Joe ERP System ("圣乔ERP系统")

Signals CISA KEV Ransomware Nuclei
Hangzhou Shengqiao Technology Co. Ltd. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

St. Joe ERP System SingleRowQueryConverter SQL Injection

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affecte

CWE-89Aug 27, 20251 related artifact
CVSS9.3v4.0EPSS3.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX