Impact
The vulnerability is an authenticated SQL injection in the fullTextSearchBlock endpoint’s method=1 query parameter, allowing attackers to inject UNION SELECT statements. This flaw permits reading the entire blocks table, bypassing publish‑access controls and exposing all document content and sensitive attributes. The weakness falls under the injection category, specifically CWE‑89.
Affected Systems
All versions of the Siyuan note‑taking application produced by siyuan‑note:siyuan that are prior to version 3.8.2 are affected. The affected product is identified by the CPE that includes b3log:siyuan and is listed as "siyuan" in the CNA vendor/product list.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity. The EPSS score is not available, so the exact likelihood of exploitation is uncertain, though the flaw is considered exploitable by authenticated users. The vulnerability is not currently listed in CISA KEV. Attackers need access to a valid user account but can then expose all document data via API calls to the vulnerable endpoint.
OpenCVE Enrichment