{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amahonelaukykms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mahonelau:kykms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-102491"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kykms (up to 8f130c2d85842d5b44caae78cc46d65e505949f7)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","vulnerability"],"_cs_type":"threat","_cs_vendors":["mahonelau"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in the kykms project maintained by mahonelau, specifically affecting all versions up to commit 8f130c2d85842d5b44caae78cc46d65e505949f7. The vulnerability exists within the QueryGenerator.doMultiFieldsOrder function inside the SqlInjectionUtil.java file. An attacker can manipulate the column argument to inject malicious SQL commands, enabling unauthorized interaction with the underlying database. The vulnerability is remotely exploitable, and proof-of-concept exploit code is publicly available, increasing the risk of active exploitation. The project utilizes a rolling release model, and no specific patch version has been issued by the vendor to address this flaw. Defenders should prioritize identifying instances of this component and implementing input validation controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute arbitrary SQL queries against the database used by the kykms component. This can lead to unauthorized data exfiltration, modification of database contents, or potential service disruption. Given the availability of public exploit code, systems utilizing this library are at a high risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all applications within the environment to identify any software integrating the mahonelau kykms library.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for suspicious characters (e.g., single quotes, semicolons, comment operators) within the column parameter targeting endpoints that utilize the QueryGenerator functionality.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and parameterized queries for all database interactions to mitigate the impact of potential SQL injection vectors.\u003c/li\u003e\n\u003cli\u003eSince the vendor has not provided a patched version, consider implementing a Web Application Firewall (WAF) rule to inspect and block malicious payloads targeting the specific vulnerable argument.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:28:33Z","date_published":"2026-09-29T16:28:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kykms-sql-injection/","summary":"A SQL injection vulnerability in the QueryGenerator.doMultiFieldsOrder function of mahonelau kykms allows remote attackers to execute arbitrary database queries via the column argument.","title":"SQL Injection Vulnerability in mahonelau kykms","url":"https://feed.craftedsignal.io/briefs/2026-09-kykms-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mahonelau:kykms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}