Impact
L-ONE v1.0.0 contains SQL injection flaws in the /attachment/getBusinessUploadList component, allowing attackers to inject crafted SQL via the busid, id, and taskid parameters. This flaw can lead to manipulation of legitimate database queries to expose confidential information, resulting in confidentiality compromise and potential data leakage.
Affected Systems
The affected system is the L-ONE application version 1.0.0. Users who expose the /attachment/getBusinessUploadList endpoint to the network are at risk.
Risk and Exploitability
The CVSS score is 6.5, a medium severity rating, and the EPSS score remains below 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is inferred to be exploitable remotely via HTTP requests to the /attachment/getBusinessUploadList endpoint. There is no indication that this flaw is currently listed in CISA's KEV catalog, and no known public exploit has been reported. Due to the lack of mitigations, the potential for exploitation remains a concern.
OpenCVE Enrichment