RULE(RULE ID:338476)

Rule General Information
Release Date: 2024-10-22
Rule Name: Wanhu ezEIP productlist.aspx SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Wanhu ezEIP is an enterprise resource planning software designed to help organizations manage all aspects of their business processes. It provides an integrated set of solutions covering various areas such as finance, supply chain management, sales and marketing, and human resources. An SQL injection vulnerability exists in its productlist.aspx endpoint, which can be exploited by an unauthenticated, remote attacker to gain access to data in the database or even gain system privileges on the server.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.