Impact
An authenticated attacker can inject SQL through the name field in the system profile form, enabling manipulation of database queries. By submitting crafted SQL statements to the profile edit endpoint, malicious users can alter credentials and obtain administrative privileges. This flaw allows a single authenticated user to elevate privileges across the application.
Affected Systems
The vulnerability affects Adianti Framework versions 5.5.0 and 5.6.0. Users deploying these versions are exposed to the described elevation of privileges.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity threat. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploitation yet. However, the presence of exploit references indicates that attackers could potentially exploit the flaw. The attack vector is inferred to be a web‑based input failure requiring authentication, making the vulnerability a moderate‑to‑high risk for systems that allow broad profile editing.
OpenCVE Enrichment