CyberRota Analysis
AI-GeneratedUTMStack versions prior to 11.2.16 are vulnerable to a SQL injection flaw in the UtmAssetGroupService.searchQueryBuilder() method, allowing authenticated attackers to inject malicious SQL through unsanitized input parameters. This vulnerability can be exploited via the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, granting attackers the ability to execute arbitrary SQL commands with DBA privileges, leading to full database access and potential filesystem manipulation. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access.