Impact
The vulnerability is a SQL injection flaw in the REST authentication endpoint of the risesoft‑y9 Digital‑Infrastructure component, specifically in Y9PlatformUtil.java. It allows attackers to inject arbitrary SQL during remote authentication requests, potentially leading to data disclosure or unauthorized data manipulation. The weakness is classified under CWE‑74 and CWE‑89, exposing confidentiality and integrity of database contents.
Affected Systems
Affected vendors/products include risesoft‑y9’s Digital‑Infrastructure, versions up to and including 9.6.7. No specific sub‑version enumeration is provided beyond the maximum affected version; any release 9.6.7 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is below 1 % yet an exploit has been published, implying that while low probability of mass exploitation remains, the vulnerability can be leveraged remotely by sending crafted authentication requests. Monitor for unauthenticated or suspicious POST requests to the authentication endpoint, as exploitation requires no prior credentials.
OpenCVE Enrichment
Github GHSA