'; } else{ echo ''; } echo '
|
|
|||
Release Date:2026/6/1
Rule Name:Hongfan iOffice Multiple Interfaces SQL Injection Vulnerability
Severity:critical
CVE ID:
| Descripiton:
|
Hongfan ioffice is a software specially designed for hospital integrated business management, including information portal, document circulation, process management, document management, meeting management, document management, leadership cockpit and other functional modules. There is an SQL injection vulnerability at the Hongfan iOffice multiple Interfaces, which allows unauthorized attackers to obtain sensitive database information and credentials, ultimately leading to server crashes. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.