Impact
Efence, developed by Thinking Software Technology, contains a classic SQL injection flaw in its file‑upload interface that allows an unauthenticated attacker to execute arbitrary SQL queries. The flaw can be leveraged to read arbitrary tables in the application’s database, potentially exposing confidential business data. The underlying weakness is a failure to properly sanitize user‑supplied input, classified as CWE‑89.
Affected Systems
The affected product is the Efence application from Thinking Software Technology. Versions prior to 1.2.67, which use database version 56 or earlier, are vulnerable. The vendor recommends upgrading to Efence 1.2.67 or newer (DB Ver 57+). Older deployments deployed before this release are at risk.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is rated High, reflecting the potential for data disclosure to any party that can reach the upload endpoint. The EPSS score is not available, but the absence from the KEV list does not reduce the likelihood of exploitation. Attackers only need to construct a malformed request to the publicly exposed upload page, meaning the scope of exploitation is relatively low‑barrier and could be automated.
OpenCVE Enrichment