S4E just found a high-severity finding from caldera detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 22, 2026

WanhuOA SQL Injection Scanner

Detects 'SQL Injection (SQLi)' vulnerability in WanhuOA.

Est. Time~1 minutes
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

WanhuOA is a widely used office automation and management software designed for organizational efficiency. It is employed by various enterprises to streamline workflow, manage documents, and enhance communication within the organization. The software serves sectors aiming for seamless project management and effective internal collaboration. WanhuOA's Document Management System assists in organizing and retrieving work files effortlessly. Users across the globe rely on its features to perform administrative tasks efficiently. Despite its capabilities, like any software, it may have vulnerabilities that require attention and patching.

SQL Injection in WanhuOA's DocumentEdit.jsp file represents a critical security flaw. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized data access. By injecting malicious SQL code, an attacker can interfere with the application's interaction with its database. This could result in data exposure, unauthorized access, or data manipulation. The severity of SQL injection stems from its potential impact on data confidentiality, integrity, and availability. Addressing this vulnerability is paramount to maintaining the security of the data managed by WanhuOA.

The SQL injection vulnerability in WanhuOA exists within the DocumentEdit.jsp endpoint. The vulnerability is exploitable when a specially crafted request is sent, allowing an attacker to alter SQL commands through the input field. The endpoint in question accepts a "DocumentID" parameter, which is critical for executing database queries. By injecting SQL commands into this parameter, an attacker can execute arbitrary SQL operations. The vulnerability makes use of time-based techniques to verify the existence of the flaw. When exploited, the response delay confirms the presence of the SQL injection, indicating potential exploitation.

When exploited, this vulnerability can lead to significant consequences, including the unauthorized access and extraction of sensitive information from the database. Attackers may gain the ability to read critical data, such as user credentials or confidential documents. Additionally, it can lead to data manipulation, deletion, or corruption, affecting the integrity of the stored information. Organizations relying on WanhuOA may face reputational damage, financial loss, and legal implications if such data breaches occur. Implementation of security measures is crucial to prevent these outcomes and protect organizational data.

REFERENCES

Solution Advice
  • Implement prepared statements and parameterized queries to prevent SQL injection.
  • Conduct regular security audits and code reviews to detect potential vulnerabilities.
  • Configure web application firewalls to monitor and block malicious requests.
  • Educate developers on secure coding practices to lessen the chance of similar vulnerabilities.
  • Keep the software and all its components updated to patch known security flaws.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WanhuOA SQL Injection Scanner | S4E