Impact
Improper neutralization of special elements used in an SQL command allows attackers to inject arbitrary SQL code, potentially reading or modifying database contents. The flaw is a classic stored‑data exploitation, classified as CWE‑89, and could lead to disclosure or alteration of sensitive information.
Affected Systems
The vulnerability affects the Products' Store application from TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company. All installations running a version prior to 030631b2 are impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the current exploitation probability is unknown; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑application interface where user input is embedded directly into SQL statements. An attacker who can submit crafted input to such an interface can execute arbitrary SQL commands, leading to data compromise, tampering, and potentially service disruption.
OpenCVE Enrichment