Impact
A SQL injection flaw exists in the Wgcloud 3.6.4 configuration file PortInfoMapper.xml. The vulnerability allows a remote attacker to inject arbitrary SQL commands, which can be used to modify database contents or metadata and therefore elevate the attacker’s privileges.
Affected Systems
The affected product is Wgcloud version 3.6.4. No other vendors or versions are listed in the CNA data, and the CPE information is not provided.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests that overall exploitation likelihood is low at present, yet the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the description that a remote attacker can exploit the web‑accessible configuration file. Exploitation requires the ability to send crafted SQL payloads through the PortInfoMapper.xml interface, which if successful could lead to privilege escalation. Patch status of affected installations is not disclosed in the provided data, but given the severity and lack of KEV listing, the vulnerability warrants prompt mitigation.
OpenCVE Enrichment