PT-2026-35240 · Unknown · Yu-Picture

Anch0R

·

Published

2026-04-26

·

Updated

2026-04-26

·

CVE-2026-7060

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions liyupi yu-picture versions prior to a053632c41340152bf75b66b3c543d129123d8ec
Description Remote SQL injection is possible via the sortField argument in the PageRequest() function within the MyBatis-Plus component of the yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java file. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.
Recommendations Apply the available patch to resolve the issue. As a temporary workaround, restrict or validate the input of the sortField argument used in the PageRequest() function.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7060

Affected Products

Yu-Picture