Impact
A classic SQL injection flaw allows an unauthenticated attacker to send a crafted request that bypasses the login page of the Appriss Insights VINE application. Once the bypass succeeds, the attacker can retrieve other users’ credentials, hijack their accounts, access or modify sensitive personal information, and perform a database dump. The vulnerability is categorized as CWE-89 and poses a severe confidentiality and integrity risk.
Affected Systems
The affected product is the Appriss Insights Victim Information Notification Exchange (VINE) application. No specific versions are listed in the CVE entry, so all deployments of this application are potentially impacted until a vendor update is applied.
Risk and Exploitability
The CVSS score of 9.3 places this issue in the Critical severity range. The EPSS score of less than 1% suggests that, although the flaw is severe, exploitation has not been widely observed. The vulnerability is not yet listed in the CISA KEV catalog. The attack vector is inferred to be remote network access, as the exploit requires only a crafted HTTP request and no prior authentication.
OpenCVE Enrichment