{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/house/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["house"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["chiuwingyan"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in the house application developed by chiuwingyan, affecting all commits up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. The flaw resides within the /paid/selectall.action endpoint, where the zuname argument fails to properly sanitize user-supplied input before being included in a database query. This vulnerability can be exploited remotely by an unauthenticated attacker to manipulate backend database operations.\u003c/p\u003e\n\u003cp\u003eThe product follows a continuous delivery model with rolling releases, meaning no specific version numbers are provided for affected or patched states. The developer was notified of the vulnerability but failed to provide a response or a corrective update. Given the public disclosure of the exploit, organizations utilizing this software should verify their deployment status against the provided commit hash and implement network-level filtering to block exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for unauthorized access to the backend database, potentially leading to the exposure of sensitive data, modification of application content, or full administrative takeover of the database layer. As a remote, unauthenticated vulnerability with a CVSS v3.1 score of 7.3, it poses a significant risk to the integrity and confidentiality of the host environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview application logs for HTTP requests directed at /paid/selectall.action containing suspicious characters in the zuname parameter, such as single quotes, semicolons, or SQL keywords.\u003c/li\u003e\n\u003cli\u003eImplement input validation and parameterized queries for the zuname argument to mitigate SQL injection risk.\u003c/li\u003e\n\u003cli\u003eMonitor webserver traffic for incoming POST or GET requests to the identified vulnerable endpoint as part of an incident response baseline.\u003c/li\u003e\n\u003cli\u003eIf the application is no longer actively maintained, consider isolating the instance from internet-facing networks to prevent external exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:29:58Z","date_published":"2026-08-06T23:29:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-19062/","summary":"A publicly disclosed SQL injection vulnerability (CVE-2026-19062) in the house application by chiuwingyan allows unauthenticated remote attackers to execute arbitrary SQL commands via the zuname parameter.","title":"SQL Injection Vulnerability in chiuwingyan house","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-19062/"}],"language":"en","title":"CraftedSignal Threat Feed - House","version":"https://jsonfeed.org/version/1.1"}