Impact
The vulnerability is a classic SQL injection flaw located in the /home/message/rubbish endpoint of GouGuOA v6.0.5 and earlier, triggered through the unsanitized 'keywords' HTTP parameter. An attacker can craft malicious input to manipulate the underlying SQL query, potentially read sensitive data, modify or delete database records, and in some configurations elevate privileges. This represents a confidentiality and integrity breach consistent with CWE‑89.
Affected Systems
The affected product is GouGuOA version 6.0.5 and any earlier releases. Users deploying these versions should immediately verify their installed version; the vulnerability persists until a fixing change is applied to the message handling code.
Risk and Exploitability
Official CVSS or EPSS ratings are not available, and the vulnerability is not listed in CISA's KEV catalog. Despite the lack of formal severity metrics, the presence of a SQL injection vector typically warrants a high severity assessment, especially given the potential for full data disclosure or modification.
OpenCVE Enrichment