Tag: sqli
All entries tagged sqli.
- CORRECTION — the 2026-W33 weekly told readers GeoServer's exploited SQL injection had no vendor fix and that taking endpoints off the internet was the whole remediation; the fix had shipped two days earlier
- Cisco Crosswork and Secure Workload ship nine CVEs where each identifier stands for a whole class of bugs — six reachable unauthenticated, three at low privilege, and no workaround for any of them
- UPDATE — the Metabase SQL injection has produced nine publicly confirmed downstream breaches, and the reason the list keeps growing is that patching the BI tool does not invalidate the database credentials it already handed over
- UPDATE — GeoServer's actively exploited jsonArrayContains SQL injection now has a fix, a published root cause and a service-dependent exploitation path: WFS 1.0 reaches top-level SQL, WFS 2.0 does not
- GeoServer: an unauthenticated SQL injection in the jsonArrayContains filter is being exploited with no CVE and no patch — and NCSC-CH has put it in front of Swiss operators
- UPDATE — the exploited Metabase zero-day now has an identifier: CVE-2026-72898 at CVSS 10.0, on CISA KEV since 11 August, with the affected ranges published per release line
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances — exploited since 3 August, and no CVE was ever assigned
- Adobe Campaign Classic APSB26-120 — three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect
- Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host
- CVE-2026-54363 and five siblings — Gladinet CentreStack: one cryptographic key shared across every installation forges a domain-administrator token, completing an unauthenticated RCE chain
- Joomla third-party-extension wave status: the wave crossed from disclosed to evidenced this week — server access logs showing exploitation requests, and 92 planted administrator accounts on one live site
- Every authentication bypass disclosed this week came from code accepting an attacker-supplied value as proof of identity — the check ran, it just validated the wrong thing
- CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
- CVE-2026-65766 and CVE-2026-65879 — SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- CVE-2026-61425 — Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- CVE-2026-63030 / CVE-2026-60137 (WP2Shell) — WordPress Core pre-auth RCE chain moves to confirmed in-the-wild exploitation and CISA KEV
- GLPI 11.0.8 / 10.0.26 — critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137) — out-of-band 7.0.2 patch, exploitation expected short-term
- Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)
- CVE-2026-59509 — cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)
- CVE-2026-57517 — Control Web Panel: pre-auth blind SQL injection to web-shell RCE (CVSS 9.8)
- Education
- CVE-2026-12789 — ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)
- Check Point chains SQL injection to RCE in LangGraph's checkpointer (CVE-2025-67644 + CVE-2026-28277)
- Mautic 7.1.2 / 6.0.9 — seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
- ILIAS LMS — nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection