PT-2026-40604 · Undefined · Undefined

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-37428

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-37428

Affected Products

Undefined