Impact
An improper neutralization of special elements in an SQL command allows a malicious actor to inject arbitrary SQL into the Loca Software CMS. This SQL injection flaw (CWE-89) can lead to unauthorized data exposure, modification, or deletion, and may enable further compromise of the underlying database. The vulnerability is documented as a high-severity threat with a CVSS score of 9.8.
Affected Systems
The vulnerability affects the Loca Software Informatics Technology Ltd. Co. CMS, versions through 06082026. No specific sub-versions are listed; any deployment of that CMS prior to a patch is considered vulnerable.
Risk and Exploitability
The CVSS score indicates a critical impact. Because the EPSS score is not available and the flaw is not yet listed in the CISA KEV catalog, the current exploitation probability is unknown, but the high severity suggests a strong likelihood of exploitation. The attack vector is inferred to be remote via the web interface, as the CMS processes external input in SQL statements. Attackers could exploit this without prior authentication if input validation is lacking.
OpenCVE Enrichment