Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
CVE-2026-14737
Description
A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected products
1- Range: 6.3.5.4
Patches
Vulnerability mechanics
References
5- ucn9h68n9289.feishu.cn/docx/RWItdiw5Go02UsxHxgNcMWBqnJcmitreexploit
- vuldb.com/cve/CVE-2026-14737mitrethird-party-advisory
- vuldb.com/submit/848640mitrethird-party-advisory
- vuldb.com/vuln/376320mitrevdb-entrytechnical-description
- vuldb.com/vuln/376320/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.