Impact
StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 contain a SQL injection flaw in the store() functions that can be exploited by a remote attacker. By inserting malicious SQL through these functions, an attacker can run arbitrary code on the server and gain access to sensitive information.
Affected Systems
The vulnerability affects the StudIP application. Versions 6.0.x older than 6.0.3 and 5.4.x older than 5.4.12 are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity flaw. No EPSS data is available, so the exploitation probability cannot be quantified precisely. The flaw is remote; an attacker must be able to reach the StudIP application over a network and send crafted requests to the store() endpoint. Successful exploitation would allow full control of the affected server and compromise confidential data.
OpenCVE Enrichment