Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)
Full Disclosuremailing list archivesFrom: disclosure via Fulldisclosure <fulldis 2026-8-18 06:17:51 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:05:48 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is 
published and a proof-of-concept is available.

Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)

Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping 
in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL SUPERUSER 
database role, so an authenticated administrator can inject a side-effect expression that schedules a cron job 
executing arbitrary commands as the postgres user. Dynamically verified.

Impact: Arbitrary command execution on the flow-analytics appliance as the postgres user inside the default privileged 
container. The attacker can disrupt monitoring, access network flow data, and take control of the host.

Advisory: https://0day-rubbish.com/blog/plixer-scrutinizer-orderby-sqli-pgcron-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer) disclosure via Fulldisclosure (Aug 17)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/66
如有侵权请联系:admin#unsafe.sh