RULE(RULE ID:333612)

Rule General Information
Release Date: 2021-06-01
Rule Name: Tongda OA v11.9 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Tongda OA is a collaborative office automation software independently developed by Beijing Tongda Xinke Technology Co., LTD. Tongda OA version 11.9 of the general/appbuilder/web/portal/workbench/upsharestatus page have SQL injection vulnerabilities, the vulnerability results from inadequate input parameter calibration, An attacker can gain server permissions by injecting malicious SQL statements into an application, performing unauthorized operations, resulting in information disclosure.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.