ZeroHour

CVE-2026-71622

SQL Injection in Zhao-github APiAdmin 5.0.1 Exposes Sensitive Data

CVSS 3.1
7.4 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-71622 is a SQL injection flaw (CWE-89) in the User.php component of Zhao-github APiAdmin version 5.0.1. A remote attacker can trigger the injection over the network; the CVSS vector indicates no privileges are required, though some user interaction may be involved, and the flaw's impact is scoped to confidentiality. Successful exploitation allows the attacker to obtain sensitive information from the application's backend database, with no stated impact to integrity or availability. Only deployments running APiAdmin 5.0.1 are identified as affected by the advisory. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Check the project's repository/advisory channels for a patched release beyond 5.0.1 and upgrade when one becomes available; no fixed version is named in the current data. As interim mitigation, restrict network access to APiAdmin, ensure the User.php component and database queries use parameterized statements or are covered by input-validation/WAF rules, and grant the application a least-privilege database account. Review access and database logs for unusual query patterns that could indicate probing.

Affected
Zhao-github APiAdmin5.0.1 (only version named in the advisory; other versions unconfirmed)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.