CVE-2026-5577
HIGHSong-Li cross_browser details Endpoint uniquemachine_app.py sql injection
Title source: cnaDescription
A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a. This affects an unknown part of the file flask/uniquemachine_app.py of the component details Endpoint. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Core 4
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-355347 | Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection
https://vuldb.com/vuln/355347
Signature, Permissions Required signature
permissions-required
VDB-355347 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/355347/cti
Third Party Advisory third-party-advisory
Submit #783502 | Song-Li cross_browser ca690f0fe6954fd9bcda36d071b68ed8682a786a SQL Injection
https://vuldb.com/submit/783502
Exploit exploit
issue-tracking
https://github.com/wing3e/public_exp/issues/24
Scores
CVSS v3
7.3
EPSS
0.0038
EPSS Percentile
29.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (2)
Song-Li/cross_browser
ca690f0fe6954fd9bcda36d071b68ed8682a786a
songli/cross_browser_fingerprinting
< 2022-01-17
Published
Apr 05, 2026
Tracked Since
Apr 05, 2026