Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-75334: Smart-web2 1.3.1 backend report module can run any SQL
CVE-2026-75334 · published 8 days ago
Summary
The reporting feature in Smart-web2 version 1.3.1 lets a user supply a text string that is stored and later executed directly against the database. An attacker could insert their own commands to read, change, or delete data. Apply the vendor's update or restrict who can use the report function until the software is patched.
Original advisory text
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportControll...
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published26 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
CVE-2026-75334 · NVD
Monitor software like this
Free during beta