Impact
The vulnerability resides in the PlanController.getImmediatePlans endpoint, where unsanitized manipulation of the argument order and sort parameters allows a remote attacker to inject arbitrary SQL into the query. This flaw can enable the attacker to read, modify, or delete data in the database, depending on the permissions of the affected account, and could lead to a compromise of sensitive environmental monitoring information.
Affected Systems
Affected only Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System versions up to and including 300R004C00B300. Administrators should verify whether their deployments run one of these versions and check for any update that addresses the SQL injection.
Risk and Exploitability
The CVSS score of 6.9 rates it as medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable remotely over the network and requires authentication only to the database, which is typically granted to the application. Consequently, the risk is moderate, but the potential impact on confidentiality could be significant if sensitive data is exposed.
OpenCVE Enrichment