[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)



0day Rubbish Research Team is publicly disclosing a vulnerability in 
Scrutinizer 19.7.0 (Plixer). The research is published and a proof-of-concept 
is available.

Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)

Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into 
a SQL ORDER BY clause with no escaping in the adminEditLang handler. The 
default configuration includes the pg_cron extension and a PostgreSQL SUPERUSER 
database role, so an authenticated administrator can inject a side-effect 
expression that schedules a cron job executing arbitrary commands as the 
postgres user. Dynamically verified.

Impact: Arbitrary command execution on the flow-analytics appliance as the 
postgres user inside the default privileged container. The attacker can disrupt 
monitoring, access network flow data, and take control of the host.

Advisory: 
https://0day-rubbish.com/blog/plixer-scrutinizer-orderby-sqli-pgcron-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/