CVE-2023-30625
HIGH EXPLOITED NUCLEIRudder Server SQLI Remote Code Execution
Title source: metasploitExploitation Summary
CVE-2023-30625 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Ege Balcı <[email protected]>, including a Metasploit module exploits/multi/http/rudder_server_sqli_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability (CVE-2023-30625) in RudderStack's rudder-server, allowing arbitrary SQL command execution and potential RCE due to PostgreSQL superuser permissions. The exploit crafts a malicious JSON payload to trigger command execution via the `copy ... to program` SQL command.
Description
rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.
Exploits (1)
This Metasploit module exploits a SQL injection vulnerability (CVE-2023-30625) in RudderStack's rudder-server, allowing arbitrary SQL command execution and potential RCE due to PostgreSQL superuser permissions. The exploit crafts a malicious JSON payload to trigger command execution via the `copy ... to program` SQL command.
Nuclei Templates (1)
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H