Impact
This vulnerability is a classic SQL injection (CWE‑89) where a malicious format query parameter is directly interpolated into the FROM clause of the Reader API. When exploited by an authenticated user, it permits injection of arbitrary SQL, enabling cross‑tenant database reads, extraction of PostgreSQL password hashes, reading and writing arbitrary files, and executing arbitrary code as the PostgreSQL OS user.
Affected Systems
The affected product is Magistrala from absmach for versions prior to 1.0.0. The specific services impacted are the timescale‑reader and postgres‑reader HTTP API endpoints. Users running any release before 1.0.0 are vulnerable, regardless of operating system or deployment environment.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of <1% shows a low probability of exploitation in the wild. Minimal prerequisites—a registered and authenticated account and knowledge that the Reader API can accept a malicious format parameter—make the vulnerability actionable for attackers with access to the API. The vulnerability is not listed in the CISA KEV catalog. Attackers may inject arbitrary SQL, elevate to superuser privileges set in PostgreSQL, and execute code as the PostgreSQL OS user by loading malicious shared objects. This would result in full database and system compromise. The potential for exploitation is higher in environments where the Reader API is reachable over the network and the default PostgreSQL superuser privileges remain in place; these conditions are inferred from the description and are not directly stated.
OpenCVE Enrichment