[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Tue, 18 Aug 2026 06:05:48 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in
Scrutinizer 19.7.0 (Plixer). The research is published and a proof-of-concept
is available.
Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)
Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into
a SQL ORDER BY clause with no escaping in the adminEditLang handler. The
default configuration includes the pg_cron extension and a PostgreSQL SUPERUSER
database role, so an authenticated administrator can inject a side-effect
expression that schedules a cron job executing arbitrary commands as the
postgres user. Dynamically verified.
Impact: Arbitrary command execution on the flow-analytics appliance as the
postgres user inside the default privileged container. The attacker can disrupt
monitoring, access network flow data, and take control of the host.
Advisory:
https://0day-rubbish.com/blog/plixer-scrutinizer-orderby-sqli-pgcron-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/