Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2972

20
FAUCET Score

CVE-2015-2972 describes multiple SQL injection vulnerabilities in Sysphonic Thetis versions prior to 2.3.0, allowing remote attackers to execute arbitrary SQL commands. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for full compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.2.0CPE matchmatch criteria
cpe:2.3:a:sysphonic:thetis:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.61%
Probability of exploitation in next 30 days
EPSS Percentile
83.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0261 is in the 71st percentile among its peer group of 51,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

jvndb.jvn.jp / jvndb/JVNDB-2015-000099
Vendor Advisory
jvn.jp / en/jp/JVN19011483/index.html
Vendor Advisory
github.com / sysphonic/thetis/commit/1b8234706e1294f41df42f3d1ccb71b983ffbe23
github.com / sysphonic/thetis/commit/4ca3f5f486759660b87d7c146f1fdc11264f56eb
github.com / sysphonic/thetis/commit/8004ee0c384daae0b28478ff8193d1990c397f57
github.com / sysphonic/thetis/commit/842e44f0c2bd7d680430bb89a3bb78fd744961f9
github.com / sysphonic/thetis/commit/a61dc72035c7ae0b06f6d7dc8b2a848ffc7db277
github.com / sysphonic/thetis/commit/c07e255d2296d50a0bffafaf66a76f8f1b53621f
github.com / sysphonic/thetis/commit/ce535a38ec92ff0f98af11ab41a425d1529a31ef
github.com / sysphonic/thetis/commit/d9ed965075634ca1a095b480b459c68445ce951d
sysphonic.com / en/thetis/THETIS-SEC-001.html
Vendor Advisory