Impact
The vulnerability allows a crafted value in the query parameters nome, perfil, or status supplied to /azcall/adm/gestao_loja/sis.php?t=consultar to be injected into a database query in thecall 10 and 11, creating a classic SQL injection flaw. This flaw (CWE‑74, CWE‑89) can enable an attacker to read, modify, or delete database contents, thereby compromising the confidentiality, integrity, and potentially availability of the application’s data.
Affected Systems
Affected systems are installations of Aster Telecom Azcall 10 or 11 that expose the HTTP endpoint /azcall/adm/gestao_loja/sis.php. The flaw resides in the HTTP Handler component that processes the consult request and is present in these product versions.
Risk and Exploitability
The CVSS base score of 6.9 reflects a medium‑to‑high severity vulnerability, while the EPSS score of < 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely by sending a malformed HTTP GET request to the vulnerable endpoint. The description does not specify authentication requirements; based on the description, it is inferred that no authentication or local privileges are required, but this inference is not explicitly stated in the source.
OpenCVE Enrichment