# CPAS-bug
CPAS audit management information system has SQL injection vulnerability
# Beijing YouDataSum Technology Co., Ltd.
domain: http://youdatasum.com
# Affected versions
```
<=v4.9
```
# Vulnerability code analysis
com/yonyou/aco/cpas/list/web/CpasListController.java line: 1545
```
@RequestMapping({"/findArchiveReportByDah"})
@ResponseBody
public DataGridView