CVE 8.7 HIGH

SQL Injection in Hydrosystem Control System_CVE-2026-34185

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.This issue was fixed in Hydrosystem Control System version 9.8.5

Basic Information

ID CVE-2026-34185
Source CERT-PL
Published Apr 9, 2026 at 09:41
Modified Apr 9, 2026 at 11:45

Affected Product

Vendor Hydrosystem
Product Control System
Affected Versions Hydrosystem Control System 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.