Impact
An authenticated SQL injection flaw within the UniFi Protect Application allows an attacker with low network privileges to inject arbitrary SQL commands. By manipulating query inputs, the attacker can bypass normal authorization checks and execute statements that elevate privileges on the host device, potentially giving full system control or enabling further exploitation.
Affected Systems
The vulnerability affects the UniFi Protect Application from Ubiquiti Inc. All versions released prior to the vendor’s fix are potentially vulnerable; the advisory does not specify a version range, so any deployment that has not yet applied the vendor’s update is at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates exploitation probability is very low, but not zero, and the vulnerability is not listed in CISA KEV, meaning no confirmed active exploitation has been reported. Exploitation requires authenticated access over the local network; there is no known unauthenticated or remote attack surface.
OpenCVE Enrichment