Executive brief
Abis Technology BAPSIS, a scientific research project management system, contains a critical security flaw that allows unauthorized individuals to access its underlying database. By exploiting this vulnerability, an attacker could steal sensitive research data, modify project records, or disrupt the system's availability. This issue can be exploited remotely over the internet without requiring any login credentials.
Technical details
A blind SQL injection vulnerability exists in Abis Technology BAPSIS due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send crafted malicious queries to the application and infer data from the database based on the application's responses. With a CVSS score of 9.8, the attack vector is network-based with low complexity and requires no user interaction or privileges. Successful exploitation can lead to full compromise of confidentiality, integrity, and availability of the database. The issue is addressed in versions starting from 202510271606.
Affected products
- Abis Technology BAPSIS before 202510271606
Timeline
- 2025-10-31: disclosed
- 2025-10-31: advisory
- 2025-10-27: patched: Based on the fixed version string date format