From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:05:48 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is
published and a proof-of-concept is available.
Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)
Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping
in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL SUPERUSER
database role, so an authenticated administrator can inject a side-effect expression that schedules a cron job
executing arbitrary commands as the postgres user. Dynamically verified.
Impact: Arbitrary command execution on the flow-analytics appliance as the postgres user inside the default privileged
container. The attacker can disrupt monitoring, access network flow data, and take control of the host.
Advisory: https://0day-rubbish.com/blog/plixer-scrutinizer-orderby-sqli-pgcron-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer) disclosure via Fulldisclosure (Aug 17)