CVE-2026-3818

HIGH

Tiandy Easy7 CMS 7.17.0 - SQL Injection

Title source: llm
STIX 2.1

Description

A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This manipulation of the argument strTBName causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.349784
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.349784
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.769536

Scores

CVSS v3 7.3
EPSS 0.0042
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
tiandy/easy7_cms 7.17.0
Published Mar 09, 2026
Tracked Since Mar 09, 2026