Impact
CentreStack before version 17.4 contains a SQL injection flaw in the GladDBFiles.SearchEx() and SearchExUnder() functions. The vulnerability is triggered by supplying a crafted x-glad-filter request header to the jsondir API endpoint, where the Field parameter is unsanitized and interpolated directly into SQL query strings. An attacker who is authenticated can execute arbitrary SQL statements, including PostgreSQL file manipulation functions lo_from_bytea() and lo_export(), which can be used to write arbitrary files to the server filesystem and ultimately enable remote code execution.
Affected Systems
The affected product is Gladinet’s CentreStack, specifically all releases prior to version 17.4.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Exploitation requires the attacker to be authenticated to the CentreStack system, which implies internal access or compromised credentials, but once achieved the attacker can gain full control of the server. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, however the high CVSS and confirmed RCE capability make it a significant threat if exploiting authenticated attackers are present.
OpenCVE Enrichment