RULE(RULE ID:338646)

Rule General Information
Release Date: 2025-01-14
Rule Name: Mamabaohe Yuezi Club ERP Management Cloud Platform GetData.ashx SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Mamabaohe Yuezi Club ERP Management Cloud platform is a set of comprehensive management software developed by Wuhan Jintongfang Technology Co., Ltd. to provide information solutions for the maternal and infant service industry. It is a combination of the needs of the industry's top maternity centers and related enterprises. SQL injection SQL injection vulnerability exists in GetData.ashx, an ERP management cloud platform. Unauthenticated malicious attackers can use the SQL injection vulnerability to obtain information in the database, and even write commands to the server under high permissions to further obtain the server system permissions.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.