CVE-2026-7727

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
04/05/2026
Last modified:
04/05/2026

Description

A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely. Upgrading to version 8.3.10 is able to mitigate this issue. You should upgrade the affected component.