Impact
This vulnerability is an SQL injection flaw in Teracity Software Technologies Inc's E-OSB platform. The failure to neutralize special characters in SQL commands allows an attacker to inject arbitrary SQL code. Because the input is directly incorporated into database queries, an attacker could read sensitive data, manipulate records, or execute destructive operations.
Affected Systems
The affected product is Teracity Software Technologies Inc's E-OSB platform, specifically all releases prior to V02.26.07.08.01. No further vendor or version details are provided in the advisory.
Risk and Exploitability
The CVSS score for this issue is 9.8, indicating critical severity. The EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw if an application processes user‑supplied input without sanitization and sends it to the database. The lack of protection likely requires external access to the application and the ability to supply injection payloads.
OpenCVE Enrichment