Guangzhou Tuchuang Computer Software Development · Interlib Library Cluster Automation Management System · CVE-2024-10946
**Name of the Vulnerable Software and Affected Versions**
Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System versions up to 2.0.1
**Description**
A critical issue has been found in the Interlib Library Cluster Automation Management System, affecting an unknown part of the file `/interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=&ROWID=`. The manipulation of the `sql` argument leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
**Recommendations**
For versions up to 2.0.1, update to the latest patched version immediately to mitigate risks.
As a temporary workaround, consider restricting access to the `/interlib/admin/SysLib` endpoint until a patch is available.
Avoid using the `sql` argument in the affected endpoint until the issue is resolved.