{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/shandong-hoteam/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18854"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PDM Product Data Management System"],"_cs_severities":["high"],"_cs_tags":["injection","sql-injection","cve-2026-18854"],"_cs_type":"advisory","_cs_vendors":["Shandong Hoteam"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability (CVE-2026-18854) has been identified in the Shandong Hoteam PDM Product Data Management System in versions up to 8.3.10. The vulnerability resides within the GetStoredClassByFilter function in the /Base/BaseService.asmx/DataService file. By sending a specially crafted 'FilterString' argument to this endpoint, an unauthenticated, remote attacker can manipulate backend database queries. This flaw poses a significant risk to organizational data integrity and confidentiality, as it enables unauthorized access to the underlying database management system. Publicly available exploit material has been disclosed, and as the vendor has not provided a resolution, administrators are urged to restrict network access to the affected web service components immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify internet-facing PDM web services utilizing the vulnerable /Base/BaseService.asmx endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the target endpoint, /Base/BaseService.asmx/DataService, responsible for handling class filtering requests.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET or POST request targeting the 'FilterString' parameter within the GetStoredClassByFilter function.\u003c/li\u003e\n\u003cli\u003eThe input is passed directly to the backend database engine without proper sanitization or parameterization.\u003c/li\u003e\n\u003cli\u003eThe injected SQL command is executed by the database, allowing the attacker to bypass access controls, exfiltrate data, or modify database entries.\u003c/li\u003e\n\u003cli\u003eIf the database service account has excessive privileges, the attacker may further leverage the injection to interact with the underlying host OS.\u003c/li\u003e\n\u003cli\u003eThe final objective is typically data exfiltration or the establishment of persistent unauthorized database access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary SQL commands against the backend database. This can lead to the unauthorized disclosure of sensitive product data, modification of existing records, or complete compromise of the database integrity. Given that the product manages proprietary engineering and product design data, the impact of a breach could include the loss of sensitive intellectual property and disruption of manufacturing processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided webserver-level detection rule to identify and block incoming requests containing suspected SQL injection patterns directed at the /Base/BaseService.asmx/DataService endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to the PDM web management interface to internal, trusted network segments via firewall controls to mitigate the remote exploitation vector.\u003c/li\u003e\n\u003cli\u003eAudit database access logs for unusual queries or bulk data retrieval patterns originating from the application service account to detect potential exploitation activity.\u003c/li\u003e\n\u003cli\u003eIf the software cannot be patched, consider placing a Web Application Firewall (WAF) in front of the application to inspect and filter the 'FilterString' parameter for SQL injection payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T02:04:04Z","date_published":"2026-08-05T02:04:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shandong-hoteam-sqli/","summary":"Shandong Hoteam PDM Product Data Management System versions 8.3.10 and earlier contain a SQL injection vulnerability in the GetStoredClassByFilter function that allows remote, unauthenticated attackers to execute arbitrary SQL commands.","title":"SQL Injection in Shandong Hoteam PDM Product Data Management System","url":"https://feed.craftedsignal.io/briefs/2026-08-shandong-hoteam-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Shandong Hoteam","version":"https://jsonfeed.org/version/1.1"}