Impact
The issue is a SQL injection flaw in src/cn/ylcto/book/servlet/BooksServlet.java caused by insufficient validation of the argument column. An attacker can craft a request that injects arbitrary SQL, potentially reading, modifying, or deleting database contents.
Affected Systems
The vulnerability affects GongShengyue OnlineBooks applications built up to a specific commit. Because the product follows a rolling release model, exact affected versions are not listed. Any deployment that has not yet upgraded past the referenced commit is exposed.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. EPSS is not available and the flaw can be exploited remotely, likely through a crafted HTTP request targeting the listSplit interface. No special conditions are required beyond access to the web interface.
OpenCVE Enrichment