Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. | |
| Title | GongShengyue OnlineBooks listSplit BooksServlet.java sql injection | |
| First Time appeared |
Gongshengyue
Gongshengyue onlinebooks |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:gongshengyue:onlinebooks:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gongshengyue
Gongshengyue onlinebooks |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-13T10:30:07.495Z
Reserved: 2026-09-12T09:01:52.390Z
Link: CVE-2026-90511
No data.
Status : Received
Published: 2026-09-13T11:17:00.050
Modified: 2026-09-13T11:17:00.050
Link: CVE-2026-90511
No data.
OpenCVE Enrichment
Updated: 2026-09-13T13:45:17Z