RULE(RULE ID:338388)

Rule General Information
Release Date: 2024-09-03
Rule Name: G-sky CMSV6 getAlarmAppealByGuid SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: G-sky CMSV6 Vehicle Positioning and Monitoring Platform boasts a development team centered around location services, wireless 3G/4G video transmission, and cloud storage services. It is dedicated to providing platform services for positioning and wireless video terminal products. The G-sky CMSV6 product covers a comprehensive video platform for products such as vehicle recorders, single-soldier recorders, network surveillance cameras, and driving recorders. Its getAlarmAppealByGuid interface has SQL injection vulnerabilities. Malicious attackers can perform unauthorized database operations through this vulnerability, which may lead to security problems such as information leakage, database tampering or denial of service.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.