Impact
A vulnerability was detected in the sar2html component of the cemtan web application. The flaw exists in an undisclosed part of the sar2html.py file used by the Search function, enabling an attacker to supply crafted input that is directly incorporated into a SQL statement. Because the injection is not properly sanitized, an attacker can execute arbitrary SQL commands against the underlying database. This leads to potential unauthorized data disclosure, modification, or deletion, and compromises the integrity and confidentiality of application data.
Affected Systems
The affected product is the cemtan sar2html web tool, version 4.0.0. No other versions or components are listed as impacted in the current advisory. The vulnerability lies in the Search feature of sar2html.py. The single known vendor product is cemtan:sar2html 4.0.0, and any deployment of this version without a remedial update is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the exploit is publicly known and can be triggered remotely via the Search argument. Attackers can form a malicious request, causing the application to run unauthorized SQL on the database. While the impact is moderate, the remote nature of the attack emphasizes the need for timely remediation.
OpenCVE Enrichment