Impact
An authenticated user can send a crafted table_name parameter to the previewData POST endpoint, which is included verbatim in a SELECT statement without safe identifier handling. The reflected payload can invoke PostgreSQL functions such as pg_read_file, pg_read_binary_file, or pg_ls_dir, allowing the attacker to read any file from the server that the database or the executing environment can access. This means configuration files, credentials, and source code may be exposed, compromising confidentiality and potentially allowing further system compromise. The weakness is a classic SQL injection (CWE‑89).
Affected Systems
The vulnerability exists in SQLBot versions prior to 1.9.0. It affects the backend component dataease:SQLBot that exposes the /api/v1/datasource/previewData API. Users running the default trusted loopback authentication configuration are at the greatest risk because the internal PostgreSQL connection can accept invalid credentials and run with superuser privileges. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity; the EPSS score is less than 1 %, suggesting a low probability of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the exploit requires authentication to the API, possession of a datasource configuration, and a trusted network configuration that allows superuser-level database access. An attacker meeting these conditions can read arbitrary files but cannot immediately execute code or modify data unless further privilege escalation is achieved. The risk remains moderate until the official patch is applied or a workaround limits the ability to invoke privileged PostgreSQL functions.
OpenCVE Enrichment