


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:07
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability (CVE-2026-7060) was discovered in the liyupi yu-picture application up to commit a053632c41340152bf75b66b3c543d129123d8ec. The vulnerability affects the PageRequest function in the PictureServiceImpl.java file of the MyBatis-Plus component. Attackers can exploit this by manipulating the sortField argument to perform SQL injection attacks remotely. The exploit has been publicly disclosed and is available for use. The project maintainers have been notified through a pull request but have not responded yet. A patch is recommended to resolve this security issue.
Technical details
Mitigation steps:
Affected products:
liyupi yu-picture
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7060
https://github.com/liyupi/yu-picture/
https://github.com/liyupi/yu-picture/issues/4
https://github.com/liyupi/yu-picture/pull/3
https://vuldb.com/submit/798612
https://vuldb.com/vuln/359633
https://vuldb.com/vuln/359633/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
