Impact
Movie_Recommend v1.0.0 contains a SQL injection weakness in the sort parameter on the /loadingmore endpoint. An attacker can supply a crafted value that is directly concatenated into a database query. This allows the attacker to retrieve arbitrary data from the underlying database, potentially exposing sensitive information such as user credentials or proprietary content. The flaw results in a confidentiality breach without requiring local access. Based on the description, the likely attack vector is remote exploitation via crafted HTTP requests to the vulnerable endpoint.
Affected Systems
The vulnerable application is Movie_Recommend version 1.0.0. No additional vendor or product details were provided in the CVE report. System administrators should identify whether their installation matches this version to confirm exposure. It is inferred that the lack of vendor or product listings indicates the application may be custom or internally developed.
Risk and Exploitability
The CVSS score is 9.8, indicating a critical severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, so there is no public evidence of exploitation yet. Attackers can reach the vulnerable parameter by sending HTTP requests to the affected endpoint from the network where the application is exposed. The likely attack vector is inferred to be remote via HTTP requests, given the input‑based nature of the flaw and the absence of privileged access requirements, allowing attackers to read any data the application is authorized to query.
OpenCVE Enrichment