Impact
Apache Syncope neutralization of special elements in SQL commands, allowing an administrator with sufficient entitlements to inject and execute arbitrary SQL via stacked queries. The flaw exists in the Audit Events search functionality where unsanitized sort parameters are used, enabling the attacker to manipulate the database query logic.
Affected Systems
Affected releases of Apache Syncope include all versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, and from 4.1.0-M0 through 4.1.1. The vendor recommends upgrading to 4.0.7 or 4.1.2 to remediate this issue.
Risk and Exploitability
The vulnerability allows attackers who can reach an administrator account to run arbitrary SQL statements. No evidence from EPSS or KEV indicates active exploitation, but the high CVSS score signals a severe potential impact. Likely the attack vector requires privileged access to the web interface, and the publicly known exploitation probability is low.
OpenCVE Enrichment