Impact
A stored SQL injection flaw exists in a reporting feature accessible only to authenticated administrators of Kiteworks Core. Through this vulnerability, an attacker could execute arbitrary SELECT statements against the underlying database, read confidential data, and potentially disrupt service availability. The flaw exemplifies CWE‑89 as it involves unsanitized user-supplied input that is incorporated into SQL commands.
Affected Systems
Kiteworks Core versions earlier than 9.5.0 are affected. Administrators with access to the reporting function on these releases are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity with significant impact if exploited. Although EPSS data is not available, the vulnerability requires authenticated administrative access, limiting the attack surface. The flaw is not listed in CISA’s KEV catalog, suggesting it is not publicly exploited at the time of disclosure. Attackers would need to log in with administrative credentials and invoke the reporting feature; no remote unauthenticated exploitation path exists. Given the potential for data exposure and service disruption, organizations should consider this a high priority.
OpenCVE Enrichment