Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51821: Shenzhou Shihan Video Conference System v.1.0 allows remote code execution

CVE-2026-51821 CVE-2026-51821
Summary

A security flaw in the Shenzhou Shihan Video Conference System v.1.0 allows a malicious user to potentially take control of the system by sending specially crafted data to the /user/getUserLogin endpoint. This could allow them to access sensitive information, disrupt the video conference service, or even install malware on the system. It's essential to update to the latest version or patch the system to prevent this issue.

Original title
SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint
Original description
SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint
Vulnerability type
CWE-89 SQL Injection
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026