GHSA-46x4-v393-xfpxCriticalCVSS 9.8

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote...

Published
August 10, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.

🔗 References (4)