CVE-2026-14737

7.3

Hanwang · e-Face General Management Platform

A SQL injection vulnerability in the Hanwang e-Face General Management Platform allows unauthenticated remote attackers to manipulate database queries via the 'order' argument.

Executive summary

A critical SQL injection flaw in the Hanwang e-Face General Management Platform 6.3.5.4 exposes the system to unauthorized database manipulation by unauthenticated remote attackers.

Vulnerability

This SQL injection vulnerability resides in the /sysAuthStr/querySysAuthStr.do endpoint. It permits unauthenticated remote attackers to inject malicious SQL commands by manipulating the 'order' argument within query parameters.

Business impact

The ability for an attacker to perform SQL injection against a management platform can lead to the exfiltration of administrative credentials, unauthorized access to sensitive records, or total system compromise. With a CVSS score of 7.3, this high-severity vulnerability represents a significant risk to organizational operations and data security.

Remediation

Immediate Action: Contact the vendor immediately to obtain and apply security updates for the e-Face General Management Platform.

Proactive Monitoring: Review system audit logs for anomalous database queries originating from the /sysAuthStr/querySysAuthStr.do endpoint.

Compensating Controls: Use a Web Application Firewall (WAF) to intercept and block traffic containing malicious SQL syntax directed at the application's API endpoints.

Exploitation status

Public Exploit Available: true

Analyst recommendation

Given the critical nature of the affected platform, organizations should treat this vulnerability with high urgency. Ensure that the platform is not exposed to the public internet and apply all vendor-provided security patches immediately upon availability to mitigate the risk of unauthorized database access.

More Hanwang CVEs