Sceawere
Vulnerability Detail
CVE-2026-88395UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GouGuOA SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 5h ago
- Vendor
- n/a
- Product
- n/a
- Attack Type
- n/a
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-05T16:17:16.957Z",
"pubdate": "2026-10-05T16:17:16.957Z",
"executiveSummary": "GouGuOA v6.0.5 and earlier versions are susceptible to a critical SQL injection vulnerability residing within the /home/message/rubbish endpoint.\nThis vulnerability is triggered through the improper sanitization of user-supplied input delivered via the 'keywords' parameter.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database query structure.\nThe primary risk implications include unauthorized data exfiltration, modification of database records, and potentially full compromise of the underlying database server.\nThis flaw grants attackers the capability to bypass standard application logic and interface directly with the database engine.\nThe vulnerability represents a significant security risk, as it permits the manipulation of sensitive information stored within the GouGuOA environment.",
"technicalDetails": "The vulnerability is identified as a classic SQL injection flaw located in the /home/message/rubbish script of the GouGuOA application.\nThe root cause of this vulnerability is the failure of the application to properly validate, sanitize, or parameterize the 'keywords' input parameter before incorporating it into a database query.\nBy manipulating the 'keywords' parameter with crafted SQL syntax, an attacker can alter the query's logic, enabling the execution of arbitrary commands against the database management system (DBMS).\nThe attack flow begins when an attacker sends an HTTP request to the /home/message/rubbish endpoint. The attacker includes a malicious payload within the 'keywords' parameter. Because the application processes this input without adequate security controls, the malicious SQL is concatenated directly into the database execution string.\nThis allows the attacker to terminate the intended query and append unauthorized statements using techniques such as UNION-based injection or boolean-based blind injection.\nThe impact of this vulnerability is severe, as it facilitates unauthorized access to sensitive application data, including user credentials, configuration settings, and proprietary business information.\nDepending on the configuration of the database user account used by the web application, an attacker may also be able to perform administrative actions, such as dropping tables, altering user privileges, or executing system-level commands if the database service is misconfigured with excessive permissions.\nThe vulnerability affects all GouGuOA versions up to and including v6.0.5. There is no indication that exploitation requires complex multi-step authentication, suggesting that the vulnerability may be reachable during normal application interaction.\nTo exploit this, an attacker only requires network access to the target web server. Once the malicious payload is submitted, the backend server parses and executes the injected SQL, returning the results or errors back through the HTTP response, which assists the attacker in further refining the exploit."
}