CVE-2021-47714
MEDIUMHasura Graphql Engine - SQL Injection
Title source: ruleDescription
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Exploits (1)
exploitdb
WORKING POC
by Dolev Farhi · pythonwebappsmultiple
https://www.exploit-db.com/exploits/49790
Scores
CVSS v3
5.5
EPSS
0.0003
EPSS Percentile
8.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (2)
hasura/graphql_engine
1.3.3
Hasura/Hasura GraphQL
1.3.3
Published
Dec 22, 2025
Tracked Since
Feb 18, 2026