Impact
A flaw in the Document Management System’s login page allows attackers to manipulate the Username parameter, causing an injection into a SQL query. This can lead to unauthorized database access or modification. The weakness is classified under CWE-74 and CWE-89 and is described as a classic SQL injection vulnerability that has been publicized and is likely exploitable from a remote location.
Affected Systems
Affected products include itsourcecode Document Management System version 1.0. According to the CNA, no additional affected releases are listed. The CPE indicates a single product line matching this version.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity impact, and the EPSS score of less than 1% implies a very low probability of exploitation at the time of reporting. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation can occur remotely via the /loging.php endpoint by sending crafted input in the Username field, leveraging the flaw to extract or modify database contents.
OpenCVE Enrichment