PT-2026-25663 · Tiandy · Integrated Management Platform

0Menc

+1

·

Published

2026-03-16

·

Updated

2026-04-13

·

CVE-2026-4232

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tiandy Integrated Management Platform version 7.17.0
Description A flaw exists in Tiandy Integrated Management Platform 7.17.0 that could allow for SQL injection. The issue is related to an unknown functionality within the file /rest/user/getAuthorityByUserId. Manipulation of the userId parameter may lead to a successful exploit. The attack can be initiated remotely, and details of the exploit have been publicly disclosed. The vendor was informed of the issue but did not provide a response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-4232

Affected Products

Integrated Management Platform