Impact
A SQL injection flaw exists in the uReport 2.2.9 endpoint /ureport/datasource/previewData, which permits an attacker to inject arbitrary SQL commands. The vulnerability can lead to the disclosure of confidential database tables and data, compromising the confidentiality and integrity of the underlying information system.
Affected Systems
The issue affects installations of uReport version 2.2.9. No additional vendor product details are available from the provided data.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. The EPSS score is lower than 1 %, suggesting a currently low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over HTTP, requiring crafted input to the previewData endpoint.
OpenCVE Enrichment