CVE-2026-18854 | Shandong Hoteam PDM Product Data Management System up to 8.3.10 DataService GetStoredClassByFilter FilterString sql injection
A vulnerability marked as critical has been reported in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection.
This vulnerability is referenced as CVE-2026-18854. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More