Impact
A SQL injection flaw in the Bottinelli Informatica Vedo Suite version 1.2.5’s api_vedo/chat endpoint allows a remote actor to supply a crafted utente_chat parameter that is inserted directly into an SQL statement. The injection can execute arbitrary SQL commands, which in turn enable an attacker to run code on the underlying system, compromising confidentiality, integrity, and availability of the affected components. This weakness correlates with CWE-89.
Affected Systems
The vulnerability affects Bottinelli Informatica Vedo Suite, specifically version 1.2.5. No other affected versions are listed, and it remains unclear whether earlier releases are vulnerable.
Risk and Exploitability
The lack of an EPSS score and KEV listing suggests that no widespread exploitation has been documented, but the ability to achieve remote code execution without authentication poses a very high risk. Because the vulnerable endpoint is exposed over the network and accepts user input, an attacker can reach it via any external connection, making remote exploitation straightforward. The absence of a CVSS score prevents a precise numerical assessment, yet the stated impact and nature of the flaw warrant treating it as high severity. The attack vector is likely remote over HTTP/HTTPS to the api_vedo/chat endpoint.
OpenCVE Enrichment