Impact
The defect is an improper neutralization of SQL syntax, allowing a blind SQL Injection that can be leveraged by an attacker to read or alter database contents. The nature of the flaw is a classic injection vulnerability (CWE-89), and the remediation is contingent on applying proper input validation or escaping. While the vendor has not specified the precise attack vector, the description indicates that blind injection is feasible, meaning an attacker can obtain information or modify data without seeing direct error messages. The potential impact for a compromised system includes unauthorized data exposure, integrity violations, and possibly further lateral movement if database credentials are leaked.
Affected Systems
TAC Information Services Internal and External Trade Inc. GoldenHorn OneIT is affected. The vulnerability applies to all versions prior to the Göbeklitepe release. No additional version details are provided beyond this boundary.
Risk and Exploitability
The CVSS score of 8.8 categorizes this flaw as High, indicating significant risk to confidentiality, integrity and availability. No EPSS score is available, so we cannot quantify current exploitation probability, but the absence of a KEV listing suggests it has not yet been widely exploited in known exploit kits. The vulnerability is best demonstrated through blind injection, implying it likely requires access to an exposed input endpoint, which could be either internal or external. Given the high score and lack of mitigation, the risk remains considerable until corrective action is implemented.
OpenCVE Enrichment