Impact
The flaw in the Group Editing feature of dayrui XunruiCMS allows an attacker to manipulate the groupid argument in the group_all_edit function, resulting in an unfiltered SQL query that can be exploited to perform malicious database operations. This injects arbitrary SQL, potentially granting the attacker read, modify, or delete access to the underlying data store and exposing sensitive information or corrupting application state.
Affected Systems
Any installation of dayrui XunruiCMS version 4.7.2 or earlier is vulnerable. The issue is confined to the Admin/Home.php controller of the Group Editing module, but because the injection can alter the data used by the entire administration interface, the impact could span the full platform if an attacker controls the injected payload.
Risk and Exploitability
The severity is rated a CVSS score of 5.1, indicating moderate risk. No EPSS score is currently published, and the vulnerability is not listed in the CISA KEV catalog, but the exploit is publicly disclosed and can be carried out remotely. An attacker who succeeds could read or modify database content, leading to data leakage or service disruption.
OpenCVE Enrichment