Impact
The vulnerability is classified as CWE‑89, indicating a SQL injection flaw that could allow an attacker to inject and execute arbitrary SQL commands. Because no publicly available exploits have been reported, the attack would require the attacker to discover and exploit the flaw manually. If successful, the attacker could gain unauthorized access to sensitive data stored in the database, potentially compromising confidentiality and data integrity of user information.
Affected Systems
The flaw affects Open‑Xchange Dovecot Community Edition (CE) and Open‑Xchange Dovecot Pro. No specific version range is supplied in the available data, so all deployed installations of these products may be at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.4 denotes a high severity, indicating that the vulnerability has a significant impact if exploited. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves exploitation of the Dovecot service over the network, requiring the attacker to craft a malicious SQL payload that is accepted by the application.
OpenCVE Enrichment