Impact
The vulnerability permits attackers to inject arbitrary SQL statements into backend tool endpoints, enabling modification or extraction of sensitive data from the application's database.
Affected Systems
Funiture 1.0.0, particularly the /sys/tool/select.json and /sys/tool/update.json interfaces. No additional version information is provided.
Risk and Exploitability
The exploitation probability is unknown (EPSS not available) and it is not listed in the CISA KEV catalog. The attack vector is inferred to be via the web application, with potential remote exploitation if the endpoints are exposed. The high severity stems from the ability to tamper with or disclose database content.
OpenCVE Enrichment