CVE-2026-79569
Deferred Deferred - Pending Action

SQL Injection in Movie_Recommend v1.0.0

Vulnerability report for CVE-2026-79569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MITRE

Description

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in Movie_Recommend v1.0.0. It exists in the sort parameter of the /loadingmore endpoint. The parameter is passed directly into a MyBatis mapper and concatenated into an SQL ORDER BY clause without sanitization, allowing attackers to inject malicious SQL statements.

Detection Guidance

To detect this SQL injection vulnerability, test the /loadingmore and /typesortmovie endpoints with crafted sort parameter values. Use time-based payloads like sort=1 AND SLEEP(5) to check for delays indicating SQL execution. Also try error-based payloads like sort=1 AND (SELECT 1 FROM (SELECT COUNT(*), CONCAT((SELECT database()), FLOOR(RAND(0)*2)) x FROM information_schema.tables GROUP BY x) y) to extract database information.

Check application logs for unusual SQL queries or errors. Inspect network traffic for requests containing suspicious sort parameter values. Verify if the application uses MyBatis with direct parameter interpolation in SQL queries.

Impact Analysis

Attackers can exploit this to access sensitive database information. They may extract database names, versions, user details, or execute arbitrary commands. The lack of authentication means anyone can target the vulnerable endpoints.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized data access risks. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. A SQL injection flaw could lead to data breaches, resulting in legal penalties and reputational damage.

Mitigation Strategies

Immediately update Movie_Recommend to a patched version if available. Implement input validation and sanitization for the sort parameter, using whitelisting for allowed values. Replace direct string interpolation in SQL queries with parameterized queries or prepared statements.

Add authentication mechanisms to protect endpoints. Deploy a web application firewall to filter malicious SQL injection attempts. Review and update MyBatis configuration to prevent direct parameter interpolation in SQL queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart