A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

Project Subscriptions

Vendors Products
Gongshengyue Subscribe
Onlinebooks Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
Title GongShengyue OnlineBooks listSplit BooksServlet.java sql injection
First Time appeared Gongshengyue
Gongshengyue onlinebooks
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:gongshengyue:onlinebooks:*:*:*:*:*:*:*:*
Vendors & Products Gongshengyue
Gongshengyue onlinebooks
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-13T10:30:07.495Z

Reserved: 2026-09-12T09:01:52.390Z

Link: CVE-2026-90511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-13T11:17:00.050

Modified: 2026-09-13T11:17:00.050

Link: CVE-2026-90511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses