← Back to search

CVE-2026-18854

7.3 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The vulnerability allows for SQL injection through manipulation of the FilterString argument in the GetStoredClassByFilter function, enabling remote code execution.
Exploitability
Exploitation is moderately easy with public disclosure and no vendor response; requires access to the affected service endpoint.
Blast radius
If exploited, could lead to full compromise of systems hosting the PDM product data management system, including potential data theft or manipulation.
Prioritized remediation
Apply immediate patches from the vendor or use alternative secure methods to filter inputs and prevent SQL injection attacks.
rcesql-injectionwebpatch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-74, CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.