Impact
This vulnerability allows an attacker to inject and execute arbitrary SQL through the Search API endpoint by manipulating the Value parameter. The injection can be performed remotely and an exploit has been released to the public.
Affected Systems
Das Parking Management System (停车场管理系统) version 6.2.0 is affected. No other versions or products are reported as impacted.
Risk and Exploitability
The CVSS score is 6.9, indicating medium severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog. An exploit has been publicly released and the attack can be performed remotely, which increases the likelihood of exploitation in environments where the Search API is exposed.
OpenCVE Enrichment