CVE-2026-75330 UNKNOWN

CVE-2026-75330

Published: 2026-08-26

Description

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…