Impact
The flaw resides in the Notes_controller::accessing_dictionary_authorization function of the stumasy application. An attacker can supply a specially crafted Password value that is concatenated directly into an SQL query, enabling arbitrary SQL execution. This can lead to the disclosure, modification, or deletion of database records, thereby compromising the confidentiality, integrity, and availability of the application data. The weakness is characterized by CWE‑74 and CWE‑89.
Affected Systems
The vulnerability affects mjperpinosa’s stumasy application. Any deployment that includes code prior to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be remains susceptible. Because release model without discrete version numbers, administrators must verify that their instances are running code from a state that includes the commit referenced in the advisory.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium severity. The EPSS score is below 1%, indicating a very low but nonzero probability of exploitation. However, a public exploit has already been released and the attack can be performed from any remote host. Although the vulnerability is not listed in the CISA KEV catalog, the combination of a public exploit and a remote vector elevates the priority for patching or implementing a temporary mitigation.
OpenCVE Enrichment