Overview
- xierongwkhd
- weimai-wetapp
Description
Statistics
- 1 Post
Fediverse
ZAST.AI identified and verified two SQL injection vulnerabilities in weimai-wetapp <= 1.0.0:
CVE-2026-3956 in /admin/auser/getAdmins
CVE-2026-3957 in /home/getLikeMovieList
Why this case matters:
the vulnerable parameters sit in two different application contexts
one path affects admin listing logic and one affects public recommendation logic
ZAST.AI validated exploitation with SQLMap and confirmed recovery of root@%
For defenders, this is a strong signal to review MyBatis-backed query flows as a class, not one endpoint at a time.
Full report: https://blog.zast.ai/vulnerability%20research/application%20security/weimai-wetapp-multiple-sql-injections/
Overview
- xierongwkhd
- weimai-wetapp
Description
Statistics
- 1 Post
Fediverse
ZAST.AI identified and verified two SQL injection vulnerabilities in weimai-wetapp <= 1.0.0:
CVE-2026-3956 in /admin/auser/getAdmins
CVE-2026-3957 in /home/getLikeMovieList
Why this case matters:
the vulnerable parameters sit in two different application contexts
one path affects admin listing logic and one affects public recommendation logic
ZAST.AI validated exploitation with SQLMap and confirmed recovery of root@%
For defenders, this is a strong signal to review MyBatis-backed query flows as a class, not one endpoint at a time.
Full report: https://blog.zast.ai/vulnerability%20research/application%20security/weimai-wetapp-multiple-sql-injections/
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post