RULE(RULE ID:338281)

Rule General Information
Release Date: 2024-07-30
Rule Name: WVP GB28181 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: WEB VIDEO PLATFORM(WVP) is a network video platform based on GB28181-2016 standard. SQL injection vulnerabilities exist in WEB VIDEO PLATFORM. Attackers can inject SQL statements through unauthorized interface /api/push/list to realize illegal operations such as reading, modifying, and forging database information.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.