Impact
Garlic‑Hub version 1.0.1 contains a classic SQL injection flaw in the ItemsRepository component. By submitting specially crafted data to untrusted input fields, an attacker can alter or execute arbitrary SQL statements against the database. This enables reading, modifying, or deleting records, thereby exposing sensitive information or corrupting data integrity.
Affected Systems
Only one product is listed, Garlic‑Hub version 1.0.1. No other vendor or product information is available, so any installation of this version is potentially vulnerable.
Risk and Exploitability
Although no exploitation probability is published and the issue is not listed in the CISA KEV catalog, SQL injection remains a high‑impact vulnerability. Attackers typically need network or application access to the component to inject payloads. If the application is exposed to untrusted users, the attack surface expands, and the flaw can be weaponized to compromise data confidentiality, integrity, or availability.
OpenCVE Enrichment