Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, commonly referred to as an SQL injection flaw. Developers failed to correctly escape user input before incorporating it into database queries, allowing an attacker to inject arbitrary SQL statements. This flaw can compromise data confidentiality, integrity, or availability by enabling unauthorized data retrieval, modification, or deletion.
Affected Systems
Dolusoft Software Technologies’ SOPLOG application is affected, specifically any release prior to version 2026.9.4.1. Systems running older versions should be catalogued and assessed.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. Though no EPSS score is currently reported, the lack of a KEV listing does not diminish the risk—an unpatched system remains highly susceptible to exploitation from a network location that can reach the vulnerable input vectors. Attackers can leverage this to execute the injected SQL without additional privileges, potentially taking full control over the database.
OpenCVE Enrichment