Full Disclosure mailing list archives

Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:05:48 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is 
published and a proof-of-concept is available.

Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)

Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping 
in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL SUPERUSER 
database role, so an authenticated administrator can inject a side-effect expression that schedules a cron job 
executing arbitrary commands as the postgres user. Dynamically verified.

Impact: Arbitrary command execution on the flow-analytics appliance as the postgres user inside the default privileged 
container. The attacker can disrupt monitoring, access network flow data, and take control of the host.

Advisory: https://0day-rubbish.com/blog/plixer-scrutinizer-orderby-sqli-pgcron-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread: