Impact
Garlic-Hub version 1.0.1 contains a classic SQL injection flaw in the ItemsRepository component. By submitting specially crafted data to untrusted input fields, an attacker can alter or execute arbitrary SQL statements against the database. This enables reading, modifying, or deleting records, thereby exposing sensitive information or corrupting data integrity.
Affected Systems
Only one product is listed, Garlic-Hub version 1.0.1. No other vendor or product information is available, so any installation of this version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical impact. The EPSS score of 0.00321, less than 1%, suggests a low probability of exploitation. Attackers typically need network or application access to the component to inject payloads. If the application is exposed to untrusted users, the attack surface expands, and the flaw can be weaponized to compromise data confidentiality, integrity, or availability.
OpenCVE Enrichment