The vulnerability is remotely reachable by an unauthenticated attacker and does not require user interaction. A path traversal sequence in the request URI is used to bypass the authentication layer, after which the codeitemid parameter can be used for UNION-based SQL injection. The record marks a public exploit, and the DDPOC page advertises a POC download after login but states that no validation environment is currently available. Exploitation evidence was first observed by the Shadowserver Foundation on July 30, 2024 UTC. VulnCheck's advisory page identifies the entry as present in the VulnCheck KEV database, while the supplied record's known_exploited field is null. The available evidence does not name a specific campaign, victim, or ransomware operation.