Impact
The flaw stems from improper neutralization of special elements in SQL commands, enabling an attacker to inject arbitrary SQL statements into the database queries. This can allow the attacker to read, modify, or delete data that is stored in the database. The impact is therefore potential data disclosure and database compromise.
Affected Systems
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software is affected for releases starting with V.4 and any version prior to V.16. Users running these versions should verify their current product version against this range.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the exact exploitation likelihood is uncertain. Based on the vulnerability description, the likely attack vector is any component that accepts user input and forwards it directly to the database, such as web forms or APIs, which could be exploited by external or internal actors to execute unauthorized SQL commands.
OpenCVE Enrichment