Impact
The issue is a SQL injection flaw in src/cn/ylcto/book/servlet/BooksServlet.java caused by insufficient validation of the argument column. An attacker can craft a request that injects arbitrary SQL, potentially reading, modifying, or deleting database contents.
Affected Systems
The vulnerability affects GongShengyue OnlineBooks applications built up to a specific commit. Because the product follows a rolling release model, exact affected versions are not listed. Any deployment that has not yet upgraded past the referenced commit is exposed.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation and no high probability of active attacks. The flaw can be exploited remotely, likely through a crafted HTTP request targeting the listSplit interface. The exploit is publicly available and may be used by attackers. The vulnerability is not listed in the CISA KEV catalog. No special conditions are required beyond access to the web interface.
OpenCVE Enrichment