Impact
An incomplete remediation of a prior SQL injection flaw allows an authenticated administrator on a workspace running in read‑only mode to send crafted SQL to the /api/search/fullTextSearchBlock endpoint, bypassing the application’s read‑only boundary and gaining unrestricted read access to the blocks database. The vulnerability enables confidential data disclosure beyond the intended read‑only restriction and is classified as CWE‑693, a system or application takeover.
Affected Systems
SiYuan Note’s SiYuan application for all released versions up to 3.8.1 is affected by this flaw. The issue is addressed in version 3.8.2 and later.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity risk. While the EPSS score is not available, the lack of a CISA KEV listing does not diminish the potential impact. Exploitation is feasible only by users with administrator privileges on a read‑only workspace, making it a privilege‑escalation scenario that can be executed via the exposed POST endpoint with no additional external conditions.
OpenCVE Enrichment