Description
A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely. Upgrading to version 8.3.10 is able to mitigate this issue. You should upgrade the affected component.
Problem types
Product status
8.3.1
8.3.2
8.3.3
8.3.4
8.3.5
8.3.6
8.3.7
8.3.8
8.3.9
8.3.10
Timeline
| 2026-05-03: | Advisory disclosed |
| 2026-05-03: | VulDB entry created |
| 2026-05-03: | VulDB entry last update |
Credits
red88-debug (VulDB User)
References
vuldb.com/vuln/360902 (VDB-360902 | Shandong Hoteam Software PDM Product Data Management System DataService GetQueryMachineGridOnePageData sql injection)
vuldb.com/vuln/360902/cti (VDB-360902 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/803268 (Submit #803268 | Shandong Hoteam Software Co., Ltd. PDM <8.3.10 SQL Injection)
ucn9h68n9289.feishu.cn/wiki/KvbxwRlmRihO8ZkT1E1c64pdngh
en.hoteamsoft.com/pdm