SQL Injection Vulnerability in Dromara MaxKey Software
CVE-2026-7699
Key Information:
Badges
What is CVE-2026-7699?
A notable security flaw has been detected in Dromara MaxKey versions up to 3.5.13, specifically within the StrUtils.checkSqlInjection function of StrUtils.java. This vulnerability allows attackers to execute SQL injection via manipulated arguments in the filtersfields parameter. The attack can be conducted remotely, making it a significant risk. Despite early notification, the vendor has not addressed this issue, and the exploit details have been made publicly available, heightening the potential for attacks.
Affected Version(s)
MaxKey 3.5.0
MaxKey 3.5.1
MaxKey 3.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
