Impact
An unauthenticated attacker can exploit an SQL injection flaw in Inout EasyRooms Ultimate Edition v1.0 by submitting malicious SQL code through the location parameter on the search/searchdetailed endpoint. This flaw allows the attacker to retrieve sensitive information from the database or alter its contents, leading to potential loss of confidentiality and integrity of the system's data. The vulnerability is categorized as CWE-89, indicating a classic SQL injection weakness.
Affected Systems
The affected product is Inoutscripts Inout EasyRooms Ultimate Edition version 1.0. No additional version ranges are specified, so any deployment running this exact version is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, and the EPSS score of less than 1% indicates the exploit is not widely observed yet. The vulnerability is not listed in the CISA KEV catalog. Attackers need only send unauthenticated POST requests to the search/searchdetailed endpoint with crafted payloads; no authentication or advanced environment preparation is required. If exploited, an attacker can exfiltrate or modify database content.
OpenCVE Enrichment