Impact
The vulnerability lies in the columns parameter of the GET /api/v3/hosts endpoint. A remote authenticated user with read‑only privileges can inject arbitrary PostgreSQL expressions into the SQL query. This allows the attacker to execute additional statements, bypass host scope restrictions, and retrieve data from other database rows or tables.
Affected Systems
The affected product is Tranquil_IT WAPT Server, versions 2.6.1.17834 and earlier. No other vendor or product versions are reported as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‐to‐high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate read‑only account capable of calling the API endpoint, making the attack moderately exploitable but contingent on legitimate authentication.
OpenCVE Enrichment