Impact
The vulnerability is a classic parameter injection flaw where unsanitized user data is embedded into a backend query. If exploited, an attacker who is already authenticated could modify that data to inject arbitrary SQL, potentially reading, modifying, or deleting sensitive application data. The flaw is directly tied to CWE‑89 and does not provide remote code execution, but it can lead to significant confidentiality and integrity breaches for an impacted deployment.
Affected Systems
Kiteworks Secure Data Forms is the affected product. No specific version information is provided in the advisory, so all installations using the optional feature mentioned should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available; therefore the current exploitation probability is unknown but could be nontrivial given the authentication requirement. The vulnerability is not listed in CISA’s KEV catalog, so there is no known widespread exploitation at this time. Likely exploitation requires an attacker to first authenticate to the application and then manipulate that authenticated session’s stored account data in the optional feature context.
OpenCVE Enrichment