Impact
Affected code is the article::getDataOfJson function in WuzhiCMS, where the title and master_table arguments are insufficiently sanitized. This flaw permits untrusted input to directly influence the SQL query, allowing an attacker to inject arbitrary SQL commands. The result is potential data exfiltration, unauthorized data modification, and other database compromises.
Affected Systems
The vulnerability exists in all releases of WuzhiCMS up to and including version 4.1.0. No specific subversions are listed, so any deployment of the CMS with those or earlier versions of the affected file is at risk.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium-risk vulnerability. The EPSS score is < 1%, and the issue is not yet listed in the CISA KEV catalog. Remote exploitation is feasible via the web interface at /index.php?m=content&f=article&v=getDataOfJson, and publicly available exploits can be leveraged. Attackers can craft malicious query parameters in the title or master_table field to execute SQL statements, compromising the integrity, confidentiality, and potentially availability of the underlying database.
OpenCVE Enrichment