Description
A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basic Organizational Structure Module. Performing a manipulation of the argument Name results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2026-03-11: | Advisory disclosed |
| 2026-03-11: | VulDB entry created |
| 2026-03-11: | VulDB entry last update |
Credits
yuan384 (VulDB User)
VulDB
References
vuldb.com/?id.350404 (VDB-350404 | FeMiner wms Basic Organizational Structure depart_add_bg.php sql injection)
vuldb.com/?ctiid.350404 (VDB-350404 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.768977 (Submit #768977 | https://github.com/FeMiner/wms Enterprise Warehouse Management System V1.0 SQL Injection)
github.com/yuan384/cve/issues/3