Impact
The vulnerability allows a user with read‑only permissions to append additional SELECT statements to an authorized query. Because the system only verifies the authorization of the first statement, the subsequent statements are executed with the same privileges. An attacker can thus retrieve credential tables and obtain password hashes for administrative accounts. This results in credential compromise and elevation of privileges with potential system‑wide impact.
Affected Systems
Manticore Software’s Manticore Search product is vulnerable in all releases from 27.0.0 up to and including 28.4.3. The issue is present in the source code that handles MySQL protocol authentication and query parsing, as shown in the file auth_proto_mysql.cpp around line 408–418 in the 28.4.4 source tree.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity. However, the EPSS score is below 1 %, meaning the probability of exploitation in the wild is low, and the vulnerability is not yet listed in the CISA KEV catalog. The most likely attack path involves an authenticated read‑only user submitting a crafted multi‑statement request that bypasses authorization checks on the subsequent SELECT clause. Because only authorization is improperly enforced, a successful request can give an attacker access to sensitive credential data without requiring elevated privileges.
OpenCVE Enrichment