CVE-2024-39309

CRITICAL

Parse Server < 6.5.7 and 7.0.0-7.1.0 - SQL Injection via PostgreSQL Configuration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-39309. PoCs published by HeavyGhost-le.

AI-analyzed exploit summary This repository contains a functional Python-based exploit for CVE-2024-39309, a PostgreSQL SQL injection vulnerability in Parse Server versions prior to 6.5.7 and 7.1.0. The exploit demonstrates database enumeration, file reading, and privilege escalation via crafted regex-based SQL injection.

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.

Exploits (1)

nomisec WORKING POC 1 stars
by HeavyGhost-le · poc
https://github.com/HeavyGhost-le/POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0

This repository contains a functional Python-based exploit for CVE-2024-39309, a PostgreSQL SQL injection vulnerability in Parse Server versions prior to 6.5.7 and 7.1.0. The exploit demonstrates database enumeration, file reading, and privilege escalation via crafted regex-based SQL injection.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Parse Server (versions < 6.5.7 and < 7.1.0)
Auth required
Prerequisites: Valid Parse Server application ID · Access to the target Parse Server endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0379
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288 CWE-89
Status published
Products (3)
npm/parse-server 0 - 6.5.7npm
parse-community/parse-server < 6.5.7
parse-community/parse-server >= 7.0.0, < 7.1.0
Published Jul 01, 2024
Tracked Since Feb 18, 2026