CVE-2026-4289: Tiandy Easy7 Integrated Management Platform getRecByTemplateId sql injection
A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4289?
CVE-2026-4289 has been classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-4289?
To fix CVE-2026-4289, update the Tiandy Easy7 Integrated Management Platform to a version later than 7.17.0.
What systems are affected by CVE-2026-4289?
CVE-2026-4289 affects the Tiandy Easy7 Integrated Management Platform versions up to and including 7.17.0.
What type of attack does CVE-2026-4289 allow?
CVE-2026-4289 allows for SQL injection attacks, which could lead to unauthorized data access or manipulation.
Where is the vulnerable function in CVE-2026-4289 located?
The vulnerable function in CVE-2026-4289 is located in the file /rest/preSetTemplate/getRecByTemplateId.