CVE-2026-62238
גבוהה 8.8
תיאור (מקור, אנגלית)
OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.2 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-5/8/2026
- CWE
- CWE-89
מוצרים מושפעים
openremote: openremote
קישורים
- https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v ExploitMitigationVendor Advisory
- https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v ExploitMitigationVendor Advisory
- https://www.vulncheck.com/advisories/openremote-sql-injection-via-crosstab-exp… Third Party Advisory