Sceawere

Vulnerability Detail

CVE-2026-88395UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GouGuOA SQL Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-05T16:17:16.957Z",
  "pubdate": "2026-10-05T16:17:16.957Z",
  "executiveSummary": "GouGuOA v6.0.5 and earlier versions are susceptible to a critical SQL injection vulnerability residing within the /home/message/rubbish endpoint.\nThis vulnerability is triggered through the improper sanitization of user-supplied input delivered via the 'keywords' parameter.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database query structure.\nThe primary risk implications include unauthorized data exfiltration, modification of database records, and potentially full compromise of the underlying database server.\nThis flaw grants attackers the capability to bypass standard application logic and interface directly with the database engine.\nThe vulnerability represents a significant security risk, as it permits the manipulation of sensitive information stored within the GouGuOA environment.",
  "technicalDetails": "The vulnerability is identified as a classic SQL injection flaw located in the /home/message/rubbish script of the GouGuOA application.\nThe root cause of this vulnerability is the failure of the application to properly validate, sanitize, or parameterize the 'keywords' input parameter before incorporating it into a database query.\nBy manipulating the 'keywords' parameter with crafted SQL syntax, an attacker can alter the query's logic, enabling the execution of arbitrary commands against the database management system (DBMS).\nThe attack flow begins when an attacker sends an HTTP request to the /home/message/rubbish endpoint. The attacker includes a malicious payload within the 'keywords' parameter. Because the application processes this input without adequate security controls, the malicious SQL is concatenated directly into the database execution string.\nThis allows the attacker to terminate the intended query and append unauthorized statements using techniques such as UNION-based injection or boolean-based blind injection.\nThe impact of this vulnerability is severe, as it facilitates unauthorized access to sensitive application data, including user credentials, configuration settings, and proprietary business information.\nDepending on the configuration of the database user account used by the web application, an attacker may also be able to perform administrative actions, such as dropping tables, altering user privileges, or executing system-level commands if the database service is misconfigured with excessive permissions.\nThe vulnerability affects all GouGuOA versions up to and including v6.0.5. There is no indication that exploitation requires complex multi-step authentication, suggesting that the vulnerability may be reachable during normal application interaction.\nTo exploit this, an attacker only requires network access to the target web server. Once the malicious payload is submitted, the backend server parses and executes the injected SQL, returning the results or errors back through the HTTP response, which assists the attacker in further refining the exploit."
}
CVE-2026-88395: GouGuOA SQL Injection Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere