Impact
The flaw in Flowring's Docpedia allows an unauthenticated user to inject arbitrary SQL statements into the application's database queries. By exploiting this vector the attacker can read sensitive data stored in the database, compromising confidentiality and potentially enabling further attacks.
Affected Systems
The vulnerability is present in Flowring's Docpedia application. No specific version numbers are listed, so all installed instances of Docpedia may be affected.
Risk and Exploitability
The published CVSS score of 8.7 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely to be widespread, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the flaw can be triggered remotely without authentication, meaning that any exposed instance of Docpedia is at risk if the patch has not been applied. An attacker could construct a payload against a publicly reachable endpoint to retrieve database contents, which could lead to data exfiltration or further lateral movement.
OpenCVE Enrichment