Impact
This vulnerability is a classic SQL injection flaw where user input is improperly escaped before being incorporated into an SQL command. The flaw permits an attacker to inject arbitrary SQL, leading to unauthorized access to, alteration of, or deletion from the underlying database. The weakness is classified as CWE-89, which indicates a failure to properly neutralize special elements used in an SQL command. The impact is the potential compromise of sensitive data and the integrity of the access control system.
Affected Systems
The affected product is Armiya Information Technologies Ltd. Co.’s Access Control System. All deployments running a build before Versiyon 2 are vulnerable. No later versions are listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, placing it in the critical category. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an external attacker sending crafted requests to the Access Control System’s input fields, possibly even without prior authentication. Exploitation would enable the attacker to read, modify, or delete data from the system’s database, thereby breaching confidentiality and integrity and potentially affecting system availability if the database is disrupted.
OpenCVE Enrichment