Description
Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Emel Basayar
References
www.exploit-db.com/exploits/50381 (ExploitDB-50381)
odine.com/solutions/gatekeeper/ (Odine Solutions GateKeeper Product Homepage)
www.vulncheck.com/...s-gatekeeper-trafficcycle-sql-injection (VulnCheck Advisory: Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection)