{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "cd74f0fec0a548aab127f46993163c8e856ce60ca6977d219d84a5994e5dc48f",
    "authored_runtime_manifest_sha256": "ea8129ea345a2affd347b12e2a47df82dec75365616f5342224d1c7336bf5584",
    "authored_verdict_sha256": "05b5d7ac1450822a01670b0c9132c95ff7ab65d773e351645eddb831822a2b3b",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Authenticated JSON-RPC host.get params groupBy and sortfield containing the same MySQL conditional SLEEP expression",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "sql_injection",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "sql_injection",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "POST /api_jsonrpc.php -> host.get -> CApiService::applyQuerySortOptions() -> ORDER BY",
  "validated_surface": "api_remote"
}
