PT-2026-26948 · Unknown · Apconw Aix-Db
Goku
+1
·
Publicado
2026-03-21
·
Atualizado
2026-03-22
·
CVE-2026-4530
CVSS v3.1
5.3
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
apconw Aix-DB versions up to 1.2.3
Description
A security flaw exists in apconw Aix-DB, specifically within the file
agent/text2sql/rag/terminology retriever.py. Manipulation of the Description argument can lead to SQL injection. The attack requires local access. The exploit has been publicly released. The vendor was contacted but did not respond.Recommendations
Versions prior to 1.2.3 should be updated. As a temporary workaround, consider restricting access to the
terminology retriever.py file to minimize the risk of exploitation.Exploit
Correção
Special Elements Injection
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apconw Aix-Db