CVE-2026-4232 describes a SQL Injection vulnerability affecting Tiandy Integrated Management Platform version 7.17.0, specifically within the /rest/user/getAuthorityByUserId endpoint when manipulating the 'userId' argument. This vulnerability is rated 7.3 (High) on the CVSSv3.1 scale, indicating it can be exploited remotely with low complexity and no required privileges or user interaction, potentially impacting confidentiality, integrity, and availability. Although the exploit has been publicly disclosed and is usable, there is no indication of active exploitation, and exploit code is not yet available in common frameworks like Metasploit or ExploitDB, with community discussion and media coverage being negligible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tiandy | Integrated Management Platform | 7.17.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.