Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

z-9527 Admin 1.0/2.0 Exposes User Data to Malicious SQL Queries

CVE-2026-3200
Summary

The user management functions in z-9527 Admin 1.0 and 2.0 are vulnerable to a security threat that allows hackers to inject malicious SQL code. This could potentially expose sensitive user data. If you use this software, update it to the latest version as soon as possible to protect your users' information.

Original title
A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /server/controller/user.js. The manipulation leads...
Original description
A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /server/controller/user.js. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 7.5
nvd CVSS3.1 7.3
nvd CVSS4.0 6.9
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026