Junglewise Threat Intelligence

CVE-2026-16252: Beijing Shenzhou Shihan Multimedia Display System SQL injection

CVE-2026-16252 · Severity: high · CVSS 7.3 · Published 2026-07-20

Executive brief

A security vulnerability exists in the Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System, a platform used for managing digital displays and multimedia content. An attacker can exploit this flaw to gain unauthorized access to the system's database, potentially leading to the theft of sensitive information or disruption of display operations. This attack can be carried out remotely over the internet without requiring any user interaction or login credentials.

Technical details

A SQL injection vulnerability exists in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System version 8.2.2. The flaw is located in the 'Staffshinel Ds.jsp' file within the '/admin/system/structure/updateStructure/deflate/Insecure/' directory. By manipulating the 'Structure_ID' argument, a remote, unauthenticated attacker can execute arbitrary SQL commands against the backend database. This can lead to unauthorized data retrieval, modification, or deletion. A public exploit (PoC) has been released, increasing the risk of exploitation.

Affected products

  • Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2

Timeline

  • 2026-07-20: disclosed
  • 2026-07-20: advisory

References