CVE-2026-90511: GongShengyue OnlineBooks listSplit BooksServlet.java sql injection
A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that exploitation is remote, requires low privileges, and does not require user interaction. Attack complexity is rated low.
Which deployments should be considered affected?
OnlineBooks versions up to commit dfc5eacc08d3b0396c266049548618f6fb9587ea are affected. Because the product uses rolling releases, affected and updated release version numbers are not disclosed.
How likely is exploitation in practice?
A public exploit is available and may be used. The vulnerability has a medium severity score of 6.3 and can affect confidentiality, integrity, and availability at low impact levels.