What is CVE-2026-18970?
A remote SQL injection vulnerability exists in Rongzhitong Visual Integrated Command and Dispatch Platform up to version 20260617, specifically in the /dm/dispatch/user/findAll file. By manipulating the 'Name' argument, attackers can inject malicious SQL queries to compromise the database. Immediate vendor-provided patching is required.
Azərbaycanca: Rongzhitong Visual Integrated Command and Dispatch Platform-un 20260617 versiyasına qədər olan versiyalarında kritik SQL injection zəifliyi aşkar edilib. Təcavüzkar `/dm/dispatch/user/findAll` faylındakı `Name` arqumentini manipulyasiya edərək uzaqdan verilənlər bazasına müdaxilə edə bilər. Sistem administratorları dərhal istehsalçı tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of Rongzhitong Visual Integrated Command and Dispatch Platform are vulnerable to the CVE-2026-18970 SQL injection?
All versions up to 20260617 are vulnerable to this critical SQL injection flaw.
How can an attacker remotely compromise the database using the CVE-2026-18970 vulnerability?
The attacker can inject malicious SQL queries by manipulating the 'Name' argument in the `/dm/dispatch/user/findAll` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.