CVE-2026-7435
HIGHSSCMS v7.4.0 SQL Injection via stl:sqlContent queryString
Title source: cnaDescription
SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise.
Scores
CVSS v3
7.2
EPSS
0.0013
EPSS Percentile
31.7%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
siteserver/SSCMS
7.4.0
Published
Apr 30, 2026
Tracked Since
May 01, 2026