Impact
Movie_Recommend v1.0.0 contains a SQL injection weakness in the sort parameter on the /loadingmore endpoint. An attacker can supply a crafted value that is directly concatenated into a database query. This allows the attacker to retrieve arbitrary data from the underlying database, potentially exposing sensitive information such as user credentials or proprietary content. The flaw results in a confidentiality breach without requiring local access.
Affected Systems
The vulnerable application is Movie_Recommend version 1.0.0. No additional vendor or product details were provided in the CVE report. System administrators should identify whether their installation matches this version to confirm exposure.
Risk and Exploitability
The CVSS score is not supplied, but SQL injection flaws are generally considered high‑severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, so there is no public evidence of exploitation yet. Attackers can reach the vulnerable parameter by sending HTTP requests to the affected endpoint from the network where the application is exposed. Given that the flaw is input‑based and does not require privileged privileges, remote attackers could leverage it to read any data the application is allowed to query.
OpenCVE Enrichment