Impact
Collectric CMU 1.0 contains a boolean‑based blind SQL injection flaw in the "lang" parameter of the login request. An attacker can send forged credentials that inject SQL through this parameter. Using time‑based blind techniques, the attacker can extract text from database tables, thereby compromising the confidentiality of stored data. The flaw does not immediately allow code execution, but it does enable the compromise of sensitive information and potentially grants an attacker the ability to alter data if further logic is exploited.
Affected Systems
The vulnerability affects the Ourenergy Collectric CMU product, version 1.0. No additional affected components or versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. An EPSS score is not reported, and the flaw is not listed in the CISA KEV catalog. The attack vector is likely remote, delivered via the publicly accessible login endpoint, and does not require authentication, making it highly attractive to attackers. The boolean‑based nature of the injection requires only the influence of the "lang" parameter, so any system exposing that endpoint to the network is a potential target.
OpenCVE Enrichment