SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79573

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

L-ONE v1.0.0 is vulnerable to multiple SQL injection flaws in the /attachment/getBusinessUploadList component, specifically through the busid, id, and taskid parameters. Exploitation of these vulnerabilities could enable attackers to retrieve sensitive information from the database by executing crafted SQL queries. Organizations using this version of L-ONE should prioritize remediation to protect against potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79573
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.