Impact
Docpedia, a product of Flowring, contains a SQL Injection flaw that allows an authenticated remote attacker to inject arbitrary SQL commands. This can result in reading, modifying, or deleting database contents, compromising the confidentiality, integrity, and availability of the application data.
Affected Systems
The vulnerability affects Flowring’s Docpedia application. No specific version information is listed in the CNA data, so any installation of this product without the patch is potentially vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 8.7, indicating a high severity and that exploitation could have serious consequences. The EPSS score is below 1 %, suggesting that widespread exploitation has not yet been observed, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers would need valid credentials to reach the vulnerable endpoints, so internal or compromised accounts pose the biggest risk.
OpenCVE Enrichment