Impact
The flaw is a classic SQL injection caused by improper neutralization of special characters in SQL statements, allowing an attacker to inject operating‑system commands through the database server. Successful exploitation grants the attacker arbitrary command execution on the host running the database, leading to loss of confidentiality, integrity, and availability of the application and underlying systems. This weakness is classified as CWE‑89.
Affected Systems
Semtek Informatics Software Consulting Trade Ltd. Co. SEM‑PMP versions up to and including 23042026 are vulnerable. No fixed version is documented; administrators should upgrade to a later release when a vendor patch becomes available.
Risk and Exploitability
The CVSS score of 9.8 flags critical severity, while the EPSS score of <1% suggests a low exploitation probability at present. However, the ability to execute arbitrary commands elevates the risk markedly. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, requiring the attacker to deliver malicious input to a reachable application endpoint, potentially via web or API interfaces, without necessarily needing authentication.
OpenCVE Enrichment