Impact
Improper neutralization of special elements used in an SQL command allows an attacker to inject arbitrary SQL code, potentially compromising the confidentiality and integrity of the database. This flaw is scored 9.8 on the CVSS scale, indicating a critical level of impact.
Affected Systems
Xpoda Türkiye Informatics Technology Inc. No Code Platform, versions starting at 4.1.3 up to but not including 4.1.4, are affected.
Risk and Exploitability
The CVSS score of 9.8 places the vulnerability in the critical range. The EPSS score of <1% indicates a very low likelihood of exploitation. The flaw is not listed in CISA's KEV catalog. It is inferred that an attacker could exploit the flaw via the platform’s web interface by submitting malicious input that is incorporated into SQL statements, provided that input sanitization is insufficient or nonexistent.
OpenCVE Enrichment