Impact
Aptabase contains a SQL injection flaw in the ClickHouse query backend that permits authenticated attackers to inject malicious parameters into Liquid SQL templates, enabling them to read event data from all tenants.
Affected Systems
The vulnerability exists in any Aptabase deployment that includes commit 5a89368; no specific version numbers are provided in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who are authenticated can supply malicious values in the EventName, CountryCode, OsName, DeviceModel, AppVersion, or SessionId parameters, injecting a UNION ALL statement into the Liquid SQL templates and bypassing the app_id tenant isolation filter across thirteen of the fifteen statistics API endpoints.
OpenCVE Enrichment