Executive brief
A SQL injection vulnerability exists in the Shenzhen Sixun Software Sixun Shanghui Group Business Management System, a platform used for retail and business operations management. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive business data or disruption of operations. Because the exploit is publicly available and the vendor has not responded to disclosure attempts, organizations using this software are at heightened risk.
Technical details
A SQL injection vulnerability exists in the /api/Dinner/PayConfig endpoint of Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. The vulnerability is caused by improper neutralization of special elements within the 'tableno' argument. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to the affected server. Successful exploitation allows for the execution of arbitrary SQL commands, which can lead to unauthorized data retrieval, modification, or deletion. Public exploit code is currently available, and the vendor has reportedly not provided a patch or response.
Affected products
- Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10
Timeline
- 2026-05-26: disclosed: Public disclosure of the vulnerability and exploit code.
- 2026-05-26: advisory