Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
The vulnerability classified as CWE-1392 (Use of Default Credentials) combined with the SQLi tag suggests that attackers with administrative privileges can inject unvalidated SQL queries through the application's administrative interface. According to vendor references, the issue concerns an unrestricted SQL console available in the administrative panel (Admin UI). Lack of proper input validation enables execution of arbitrary queries directly on the database.
An attacker can gain full access to the application database, read, modify, or delete stored archaeological and configuration data, and potentially perform operations at the database system level, leading to violations of confidentiality, integrity, and availability of the entire system.
Apply patches available from the vendor according to the references. Additionally, it is recommended to restrict access to the administrative panel only to trusted networks and implement strong access control for the SQL console in the Admin UI.
OpenAtlas version 8.11.0 developed by the Austrian Archaeological Institute
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCraws Openatlas
APPCraws< 8.12.0
Related vulnerabilities
Hardcoded hasło administratora w OpenAtlas v8.11.0
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8...
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows ...
Nieprawidłowa kontrola dostępu w Austrian Archaeological Institute Openatlas przed wersją v8.12.0 pozwala atak...
Podatność w Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 pozwala zda...