Executive brief
Movie_Recommend is an open-source movie recommendation system. An attacker can inject malicious SQL commands through the sort parameter in the /loadingmore endpoint without needing to log in, allowing them to extract sensitive database information such as usernames, passwords, and other confidential data stored in the database.
Technical details
This is a SQL injection vulnerability in the sort parameter of the /loadingmore and /typesortmovie endpoints. The application directly passes user input from the sort parameter into a MyBatis mapper's ORDER BY clause using string concatenation (${sort}) rather than parameterized queries. The vulnerable code is in MovieMapper.xml where the sort value is concatenated into "ORDER BY ${sort} desc". Since the MySQL connection is configured with allowMultiQueries=true, attackers can execute stacked queries. Both endpoints are accessible without authentication as there is no login requirement or Spring Security framework. Attackers can exploit this via time-based blind injection (using SLEEP) or error-based injection (using extractvalue) to extract database names, versions, users, and other sensitive information. A patch should replace the vulnerable string concatenation with parameterized queries or input validation/whitelisting.
Affected products
- Movie_Recommend Movie_Recommend v1.0.0
Timeline
- 2026-09-08: disclosed