S
QL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do.
References
| Link | Resource |
|---|---|
| https://github.com/xnx3/wangmarket/issues/7 | Exploit Issue Tracking |
| https://github.com/xnx3/wangmarket/issues/7 | Exploit Issue Tracking |
Configurations
History
30 Jan 2026, 16:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wang.market wangmarket
|
|
| CPE | cpe:2.3:a:wang.market:wangmarket:4.10:*:*:*:*:*:*:* |
21 Nov 2024, 07:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/xnx3/wangmarket/issues/7 - Exploit, Issue Tracking |
Information
Published : 2023-04-28 20:15
Updated : 2026-01-30 16:51
NVD link : CVE-2023-26813
Mitre link : CVE-2023-26813
CVE.ORG link : CVE-2023-26813
JSON object : View
Products Affected
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')