A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
An attacker with network access and an account with low privileges can exploit a series of SQL Injection vulnerabilities present in the UniFi Talk application. Through crafted SQL queries injected into vulnerable application endpoints, it is possible to gain unauthorized access to data and escalate privileges at the host device level. The vulnerability requires only low-privilege authentication, which significantly lowers the threshold for its exploitation.
An attacker can perform privilege escalation on the host device, potentially gaining full control of the system, including access to sensitive data, ability to modify configuration, and compromise of service integrity and availability.
Security patches from the manufacturer should be applied according to references — details in Security Advisory Bulletin 066 available at: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
UniFi Talk application — versions indicated in manufacturer references (Security Advisory Bulletin 066)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HUi Unifi Talk Application
APPUi< 5.2.2
Related vulnerabilities
SSRF w UniFi Talk Application — DoS i ominięcie uwierzytelnienia
Privilege Escalation w UniFi Talk Application (Improper Access Control)
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
Command Injection w UniFi OS via nieprawidłowa walidacja wejścia