SQL Injection Vulnerability in GongShengyue OnlineBooks Affects User Data Security
CVE-2026-90511
Key Information:
- Vendor
Gongshengyue
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90511?
A vulnerability has been identified in GongShengyue OnlineBooks that allows for SQL injection via the listSplit component's BooksServlet.java file. An attacker can manipulate the argument column leading to unapproved database access, potentially exposing sensitive information. This issue impacts versions of the product up to a specified commit but does not have explicit version disclosures due to the software's rolling release model. As details of the exploit become public, immediate attention is recommended to mitigate potential security risks.
Affected Version(s)
OnlineBooks dfc5eacc08d3b0396c266049548618f6fb9587ea
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
