CVE-2026-9465: Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9465?
The severity of CVE-2026-9465 is high, with a score of 7.3.
How do I fix CVE-2026-9465?
To fix CVE-2026-9465, update the Tiandy Easy7 Integrated Management Platform to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-9465?
CVE-2026-9465 is classified as a SQL Injection vulnerability.
Can CVE-2026-9465 be exploited remotely?
Yes, remote exploitation of CVE-2026-9465 is possible through the vulnerable component.
Which version of Tiandy Easy7 Integrated Management Platform is affected by CVE-2026-9465?
CVE-2026-9465 affects Tiandy Easy7 Integrated Management Platform version 7.17.0.