Impact
The vulnerability exists in the strip_data function of search.php in the Search Module of SoftNews Media Group DataLife Engine 18.0. By manipulating the story argument, an attacker can inject arbitrary SQL statements. This allows the attacker to read, modify, or delete database records, which could lead to data loss, unauthorized disclosure, or further compromise of the site.
Affected Systems
SoftNews Media Group DataLife Engine version 18.0. This version uses the Search Module containing the vulnerable strip_data function.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity, but the remote attack vector and publicly available exploit raise the risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, attackers can trigger the injection from an external host and potentially gain unauthorized database access.
OpenCVE Enrichment