Impact
CTMS developed by Sunnet contains a SQL Injection vulnerability that allows an authenticated remote attacker to inject arbitrary SQL commands. This flaw enables the attacker to read sensitive information, alter database records, or delete data entirely. The weakness is classified as CWE-89, reflecting unsanitized input in database queries.
Affected Systems
Sunnet CTMS is identified as the affected product. No specific version details are currently available, meaning every release of the CTMS software may be vulnerable until Sunnet releases a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits. The attack vector is authenticated remote, requiring the attacker to be logged in to the application. Once authenticated, the attacker can execute arbitrary SQL commands, leading to data compromise. The absence of an immediate patch increases the risk for systems that have not yet updated.
OpenCVE Enrichment