top of page
perceptive_background_267k.jpg

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture…

Published:

25 april 2026 om 22:00:00

Alert date:

26 april 2026 om 23:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A SQL injection vulnerability (CVE-2026-7060) was discovered in the liyupi yu-picture application up to commit a053632c41340152bf75b66b3c543d129123d8ec. The vulnerability affects the PageRequest function in the PictureServiceImpl.java file of the MyBatis-Plus component. Attackers can exploit this by manipulating the sortField argument to perform SQL injection attacks remotely. The exploit has been publicly disclosed and is available for use. The project maintainers have been notified through a pull request but have not responded yet. A patch is recommended to resolve this security issue.

Technical details

Mitigation steps:

Affected products:

liyupi yu-picture

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page