Impact
Netartmedia Vlog System contains an uncontrolled SQL injection flaw that can be triggered through the email parameter in the forgotten_password module. An attacker can send a crafted POST request to index.php with malicious code in the email field, allowing manipulation of database queries and extraction of sensitive data. The effect is the compromise of confidentiality; there is no direct evidence of integrity or availability impacts in the description.
Affected Systems
The vulnerability applies to Netartmedia Vlog System. No specific version information is provided by the vendor, so all deployed installations of the product are potentially affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Because the flaw requires no authentication and operates over the web through a standard POST endpoint, an unauthenticated attacker can exploit it remotely. While EPSS data is unavailable, the lack of an authentication barrier and the high CVSS suggest a non-negligible exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment