CVE-2026-79573: SQL Injection
L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Affected Software
Event History
Frequently Asked Questions
Which inputs should be prioritized for testing and remediation?
The affected component is /attachment/getBusinessUploadList, and the reported SQL injection vectors are the busid, id, and taskid parameters. Review every route or integration that exposes this component and accepts those parameters.
What could an attacker obtain through successful exploitation?
A successful crafted SQL statement can allow access to sensitive database information. The provided information does not state whether modification, deletion, or code execution is possible.
Which versions are confirmed affected?
The reported affected version is L-ONE v1.0.0. No fixed version, mitigation, or configuration prerequisite is provided.