在 1.0.0 版本之前的 Magistrala 软件中, 和 HTTP API 服务存在 SQL 注入漏洞。已认证的攻击者可以通过提供一个恶意的 查询参数触发该漏洞,该参数会被直接拼接进 SQL 语句的 子句中,且未进行参数化或标识符引号处理。拥有自注册账户的攻击者可以替换任意子查询,从而实现跨租户数据库读取、提取 中的密码哈希值、读写任意文件,并通过加载攻击者提供的共享对象,以 操作系统用户身份执行任意代码。由于默认的 PostgreSQL 角色配置,所有注入的 SQL 语句均以超级用户权限执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| absmach | magistrala | 0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet