CVE-2023-52286: Tencent Distributed SQL

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.

Affected products

  • Tencent Tencent Distributed SQL: up to and including 1.8.5

Published 2023-12-31. Last modified 2026-06-17.