Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Syncope
APPApache3.0.0 – 3.0.164.0.0 – 4.0.7 (excl.)4.1.0 – 4.1.2 (excl.)
Related vulnerabilities
Apache Syncope — privilege escalation do poziomu administratora przez REST API
Apache Syncope – ominięcie sandboxa Groovy przez administratora
Apache Syncope — RCE przez niebezpieczne wykonywanie skryptów Groovy
Apache Syncope: Wykonanie kodu Groovy bez sandbox przez BPMN REST API
Apache Syncope: Server-Side Template Injection w szablonach e-mail (RCE)