Impact
The vulnerability is an authenticated blind SQL injection in the /api/events/search endpoint of Scada-LTS. By inserting crafted values into the sortBy array, an attacker can directly influence the SQL ORDER BY clause. This allows time‑based and boolean‑based injection that can pull arbitrary data, including password hashes for all user accounts, through repeatable queries.
Affected Systems
Scada‑LTS 2.8.1‑release‑candidate build 0 is affected. Any user authenticated with the ROLE_USER, ROLE_ADMIN, or ROLE_PUBLIC roles can send requests to /api/events/search. The application does not apply sanitization or parameterisation to the sortBy values, exposing the application to data extraction attacks.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1 %, suggesting a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The required preconditions include valid credentials for any of the accepted roles, meaning the attack vector is internal or requires credential compromise. If an attacker gains legitimate access, the blind injection can be executed to retrieve sensitive credential material from the database.
OpenCVE Enrichment