CVE-2026-7435

HIGH

SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString

Title source: cna
STIX 2.1

Description

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise.

Scores

CVSS v3 7.2
EPSS 0.0013
EPSS Percentile 31.7%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
siteserver/SSCMS 7.4.0
Published Apr 30, 2026
Tracked Since May 01, 2026