CVE-2026-71622: SQL Injection
Published Sep 4, 2026
·Updated
SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component
Affected Software
1 affected component
Zhao-github ApiAdmin=5.0.1
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable. The available information does not state that authentication or other prerequisites are required.
2
What is the known impact of successful exploitation?
A remote attacker may obtain sensitive information through the SQL injection flaw in the User.php component.
3
Which release is identified as affected?
The reported affected release is Zhao-github ApiAdmin version 5.0.1.