CVE-2026-16252

A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. The manipulation of the argument Structure_ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Configurations

No configuration.

History

20 Jul 2026, 16:16

Type Values Removed Values Added
References
  • () https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w -

20 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 15:16

Updated : 2026-07-20 17:14


NVD link : CVE-2026-16252

Mitre link : CVE-2026-16252

CVE.ORG link : CVE-2026-16252


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')