Impact
Unsanitized sort parameters in the Task search feature enable unsanitized input to be incorporated into backend SQL statements. The flaw belongs to CWE-89 and allows an attacker to inject and execute arbitrary SQL commands, potentially reading, modifying, or deleting data in the database that backs Apache Syncope. The sole prerequisite is the ability to perform a Task search with sufficient entitlements.
Affected Systems
The vulnerability affects Apache Syncope, authored by the Apache Software Foundation. Versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are impacted. The fix is included in version 4.0.8 and 4.1.3.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability; the vulnerability is not listed in the CISA KEV catalog. The flaw allows any administrator who can perform a Task search to inject arbitrary SQL through the unsanitized sort clause, potentially executing stacked queries that can read, modify, or delete data in the backend database. Attackers require administrative entitlements, but once in place, the impact spans the entire database used by Syncope.
OpenCVE Enrichment