Sceawere
Vulnerability Detail
CVE-2026-102491UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in kykms QueryGenerator
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 10h ago
- Vendor
- mahonelau
- Product
- kykms
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. The manipulation of the argument column leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-29T15:17:17.813Z",
"pubdate": "2026-09-29T15:17:17.813Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified within the mahonelau kykms project, specifically affecting the QueryGenerator.java component.\nThe vulnerability resides in the QueryGenerator.doMultiFieldsOrder function, where the 'column' argument is processed without adequate sanitization or parameterized querying.\nThis flaw allows remote, unauthenticated attackers to manipulate SQL queries, potentially leading to unauthorized data exfiltration, modification, or complete compromise of the underlying database.\nThe risk is exacerbated by the availability of public exploits, increasing the likelihood of active exploitation.\nAs the product utilizes a rolling release model, no specific version numbers are provided, and users should assume all versions up to commit 8f130c2d85842d5b44caae78cc46d65e505949f7 are vulnerable.\nThe vendor has remained unresponsive to disclosure efforts, necessitating immediate manual remediation by consumers of the software.",
"technicalDetails": "The vulnerability stems from improper input validation and unsafe construction of SQL queries within the QueryGenerator.doMultiFieldsOrder method in the QueryGenerator.java file. The application takes input supplied via the 'column' argument and directly incorporates it into the ORDER BY clause of a database query without employing parameterized queries or prepared statements.\nIn the context of SQL injection, this behavior allows an attacker to inject arbitrary SQL syntax into the application's database interactions. By providing a crafted 'column' parameter, an attacker can manipulate the structure of the resulting SQL statement to alter the query's logic, bypass authentication mechanisms, or extract sensitive data stored within the database.\nThe attack flow begins when an external, remote attacker sends a crafted request containing malicious SQL payloads directed at an endpoint that utilizes the QueryGenerator.doMultiFieldsOrder function. Because the input is not sanitized or bound to variables, the database engine interprets the injected strings as executable SQL commands rather than literal data.\nFor instance, an attacker could terminate the intended SQL query and append unauthorized commands using UNION-based techniques to exfiltrate information from other tables, or utilize error-based injection to map the database schema. The impact of successful exploitation is significant, potentially granting the attacker complete read/write access to the database, leading to loss of confidentiality, integrity, and availability of the application data.\nThis vulnerability is classified as remote because it does not require authentication or localized access to the server, as the vulnerable function can be reached via public-facing input vectors. Since no security controls (such as prepared statements) are implemented at the entry point of the function to treat the 'column' parameter as untrusted data, the injection is highly feasible.\nThe lack of vendor response and the public availability of exploits further elevate the criticality of this finding, as automated tools and manual efforts can easily identify and weaponize the flaw in production environments using the affected component."
}