Impact
The vulnerability enables an attacker to insert arbitrary SQL code by manipulating the Login parameter in the users.php file of the SmartHomeAdatum login component. This flaw arises from improper neutralization of special characters and the use of unsanitized, non-parameterized queries (CWE-74 and CWE-89). If exploited, the attacker could read, modify, or delete data stored in the underlying database, compromising both confidentiality and integrity.
Affected Systems
The affected product is sergomanov SmartHomeAdatum, specifically an unknown function within the users.php file of the Login component. The system uses a rolling release model and no specific affected or fixed versions are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, but the EPSS score of <1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack execution is possible remotely by supplying crafted input to the Login field. Given the low exploitation likelihood, the overall risk is moderate, yet defensive controls should be applied until a vendor fix becomes available.
OpenCVE Enrichment