CVE-2023-25157

CRITICAL EXPLOITED NUCLEI LAB

Osgeo Geoserver < 2.18.7 - SQL Injection

Title source: rule

Description

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.

Exploits (9)

nomisec WORKING POC 170 stars
by win3zz · infoleak
https://github.com/win3zz/CVE-2023-25157
nomisec WRITEUP 14 stars
by murataydemir · remote
https://github.com/murataydemir/CVE-2023-25157-and-CVE-2023-25158
nomisec SCANNER 10 stars
by 0x2458bughunt · infoleak
https://github.com/0x2458bughunt/CVE-2023-25157
nomisec WORKING POC 3 stars
by charis3306 · remote
https://github.com/charis3306/CVE-2023-25157
nomisec WORKING POC 3 stars
by 7imbitz · remote
https://github.com/7imbitz/CVE-2023-25157-checker
github WORKING POC 2 stars
by Pr0t0c01 · pythonpoc
https://github.com/Pr0t0c01/CVEs/tree/main/GeoServer_CVE-2023-25157
nomisec WORKING POC 2 stars
by dr-cable-tv · infoleak
https://github.com/dr-cable-tv/Geoserver-CVE-2023-25157
nomisec WORKING POC
by custiya · infoleak
https://github.com/custiya/geoserver-CVE-2023-25157
nomisec SCANNER
by Rubikcuv5 · poc
https://github.com/Rubikcuv5/CVE-2023-25157

Nuclei Templates (1)

GeoServer OGC Filter - SQL Injection
CRITICALVERIFIEDby ritikchaddha,DhiyaneshDK,iamnoooob,rootxharsh
Shodan: title:"geoserver" || http.title:"geoserver"
FOFA: title="geoserver" || app="geoserver"

Scores

CVSS v3 9.8
EPSS 0.9398
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull vulhub/geoserver:2.22.1
docker pull postgis/postgis:14-3.3-alpine
+6 more repos

Details

VulnCheck KEV 2020-09-22
CWE
CWE-89
Status published
Products (2)
org.geoserver.community/gs-jdbcconfig 0 - 2.21.4Maven
osgeo/geoserver < 2.18.7
Published Feb 21, 2023
Tracked Since Feb 18, 2026