What is CVE-2026-18854?
A critical SQL injection vulnerability has been identified in Shandong Hoteam PDM Product Data Management System. The flaw in the GetStoredClassByFilter function within /Base/BaseService.asmx/DataService allows remote attackers to manipulate the FilterString argument. Immediate patching of affected systems is strongly recommended.
Azərbaycanca: Shandong Hoteam PDM Məhsul Məlumat İdarəetmə Sistemində kritik SQL injection zəifliyi aşkar edilib. /Base/BaseService.asmx/DataService faylındakı GetStoredClassByFilter funksiyası vasitəsilə FilterString arqumenti manipulyasiya edilərək uzaqdan kod icrası mümkündür. Təsirə məruz qalan sistemlərin dərhal yamaqlanması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which component of the Shandong Hoteam PDM system contains the CVE-2026-18854 vulnerability?
The GetStoredClassByFilter function in the /Base/BaseService.asmx/DataService file.
What can be achieved through the CVE-2026-18854 SQL injection vulnerability?
Remote code execution (RCE) can be achieved by manipulating the FilterString argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.