Impact
The vulnerability permits any authenticated user to submit arbitrary SQL queries through a privileged dashboard Excel export endpoint that is designed for administrative use only. This improper authorization flaw allows attackers to bypass role‑based access controls and retrieve sensitive database contents as a downloadable spreadsheet, effectively providing data exfiltration capabilities.
Affected Systems
Impact applies to TIM Flow from TIM Solutions, affecting all installations running a version earlier than 26.0.6.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. The EPSS score is currently not available, although the flaw is accessible to any authenticated user, meaning the exploitation probability depends primarily on the presence of valid credentials. The vulnerability is not listed in the CISA KEV catalog. Attackers would use a legitimate user account with dashboard access to craft and submit malicious SQL queries to the export endpoint, download resulting data as a spreadsheet, and thereby expose business‑critical information.
OpenCVE Enrichment