Impact
Paroiciel 11.20 contains an unauthenticated SQL injection flaw where an attacker can inject malicious SQL code via the tRecIdListe parameter in GET requests to the trec.php endpoint. This flaw permits execution of arbitrary SQL statements, enabling the attacker to retrieve sensitive data such as database table and column names. The vulnerability does not allow direct modification of data according to the official description, but it exposes confidential information that could be leveraged by further attacks.
Affected Systems
The flaw is limited to Paroiciel version 11.20. No other product versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. If the Paroiciel instance is accessible from the internet, the flaw can be exploited without authentication, making the risk significant for exposed deployments.
OpenCVE Enrichment