CVE-2021-47714
MEDIUMHasura GraphQL 1.3.3 - Local File Read via SQL Injection in Query Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47714. PoCs published by Dolev Farhi.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in Hasura GraphQL 1.3.3 to perform a local file read via the `pg_read_file` PostgreSQL function. It sends a crafted SQL query through the Hasura API to read arbitrary files from the server.
Description
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Exploits (1)
This exploit leverages a SQL injection vulnerability in Hasura GraphQL 1.3.3 to perform a local file read via the `pg_read_file` PostgreSQL function. It sends a crafted SQL query through the Hasura API to read arbitrary files from the server.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N