Impact
EFence, developed by Thinking Software Technology, contains a SQL Injection flaw that allows an unauthenticated remote attacker to embed arbitrary SQL commands. The vulnerability can be exploited to read contents from the underlying database, potentially exposing sensitive data. This flaw is an instance of CWE-89 and results primarily in data disclosure rather than modification.
Affected Systems
The affected product is Thinking Software Technology’s EFence. All releases prior to 1.2.67 with database version below 57 are vulnerable. Users should update to EFence 1.2.67 or later, which includes the fix.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Exploit probability is not documented (EPSS not available) and the vulnerability is not in the CISA KEV catalog. Based on the description, the attack vector is remote and requires no authentication. The lack of authentication requirements combined with the potential to expose database content makes this a significant risk for any installation exposed to the network.
OpenCVE Enrichment