Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rghc-mxjc-cmxr

Опубликовано: 23 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.8

Описание

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

EPSS

Процентиль: 5%
0.00021
Низкий

6.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.5
nvd
около 2 месяцев назад

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

EPSS

Процентиль: 5%
0.00021
Низкий

6.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-89