CyberRota Analysis
AI-GeneratedA SQL injection vulnerability exists in the Notes_controller::search_scratch_data function of mjperpinosa's stumasy application, allowing remote attackers to manipulate the argument field_name. This weakness could lead to unauthorized access to the database, potentially compromising sensitive information. Organizations using this application should prioritize patching this vulnerability, especially those relying on the affected version for critical operations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. The impacted element is the function Notes_controller::search_scratch_data of the file application/PHP/objects/notes/search_scratch_data.php. This manipulation of the argument field_name causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.