Junglewise Threat Intelligence

CVE-2026-18854: Shandong Hoteam PDM SQL injection in GetStoredClassByFilter

CVE-2026-18854 · Severity: high · CVSS 7.3 · Published 2026-08-05

Technologies: Shandong Hoteam Pdm.

Executive brief

Shandong Hoteam PDM is a product data management system used by enterprises to organize and control product information. A SQL injection vulnerability in the GetStoredClassByFilter function allows remote attackers to execute arbitrary SQL queries by manipulating the FilterString parameter, potentially exposing or modifying sensitive product data without authentication.

Technical details

The vulnerability is a SQL injection flaw in the GetStoredClassByFilter method of the DataService endpoint (/Base/BaseService.asmx/DataService) in Shandong Hoteam PDM up to version 8.3.10. The FilterString parameter is insufficiently sanitized before being used in SQL queries, allowing an attacker to inject malicious SQL code. The attack is remotely exploitable without requiring authentication. An attacker can leverage this to read, modify, or delete database records, potentially compromising confidential product and business information. The vendor did not respond to early disclosure attempts.

Affected products

  • Shandong Hoteam PDM up to 8.3.10

Timeline

  • 2026-08-05: disclosed

References