Summary
There is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API.
Details & PoC
As stated by the security policy, details and a PoC will be in the first comment of this report.
Impact
This allows extraction of arbitrary data from the database. The vulnerability does not require administrative access and was tested in versions 8.6.0-8.8.0.
Summary
There is an authenticated, blind (time-based) SQL-injection inside the
appMetadata-operation of the GraphQL-API.Details & PoC
As stated by the security policy, details and a PoC will be in the first comment of this report.
Impact
This allows extraction of arbitrary data from the database. The vulnerability does not require administrative access and was tested in versions 8.6.0-8.8.0.