Description
A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alarm Preview. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-04-04: | Advisory disclosed |
| 2026-04-04: | VulDB entry created |
| 2026-04-04: | VulDB entry last update |
Credits
xcxr (VulDB User)
References
vuldb.com/vuln/355333 (VDB-355333 | AutohomeCorp frostmourne Alarm Preview previewData httpTest sql injection)
vuldb.com/vuln/355333/cti (VDB-355333 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/782969 (Submit #782969 | AutohomeCorp frostmourne <= 1.0 SQL Injection)
fx4tqqfvdw4.feishu.cn/...Y9Ax6OsScJ3Blnxf?from=from_copylink