Impact
The vulnerability stems from a lack of input validation on the tableName parameter sent to the /sys/dbConnect/data endpoint of mfish‑nocode‑pro. By injecting malicious SQL code, an attacker can manipulate the query constructed by the application, leading to unauthorized retrieval of database contents. This flaw aligns with the classic SQL injection weakness and can compromise the confidentiality of sensitive data.
Affected Systems
The affected product is mfish‑nocode‑pro, version 1.0.0. No other vendors or versions are listed as impacted.
Risk and Exploitability
The vulnerability is a SQL injection (CWE‑89) with a CVSS score of 9.8, indicating a critical severity. The EPSS score, which estimates how likely the flaw is to be exploited, is < 1%, suggesting very low current exploitation probability, and the flaw is not listed in CISA's KEV catalog. The attack vector is likely network-based, with an attacker sending a crafted request to the /sys/dbConnect/data endpoint containing a malicious tableName value. Successful exploitation would allow the attacker to read sensitive database contents and potentially modify data, depending on database user privileges.
OpenCVE Enrichment