[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)
Logo Netsis NetOpenX REST 2.0.6.9 allows unauthenticated SQL injection that can run commands as SYSTEM.
0day Rubbish Research Team disclosed a flaw in Logo Netsis NetOpenX REST 2.0.6.9, the REST API gateway for the Netsis enterprise ERP suite. An unauthenticated SQL injection in the OAuth 2.0 token endpoint can lead to operating-system command execution through SQL Server xp_cmdshell. The issue is scored 9.8 and mapped to CWE-89, CWE-306, and CWE-78. The post cites no CVE and does not report exploitation in the wild.
- Affects Logo Netsis NetOpenX REST 2.0.6.9, also called Netsis Nox REST.
- Unauthenticated SQL injection in the OAuth 2.0 token endpoint.
- Injection can reach SQL Server xp_cmdshell and run commands as SYSTEM.
- Scored 9.8 and mapped to CWE-89, CWE-306, and CWE-78.
Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Logo Netsis NetOpenX REST 2.0.6.9 (also distributed as Netsis Nox REST), the REST API gateway of the Netsis enterprise ERP suite. Type: unauthenticated SQL injection in the OAuth 2.0 token endpoint leading to operating-system command execution via SQL Server xp_cmdshell (CWE-89, CWE-306, CWE-78). A single POST /api/v2/token carrying no client and no user credentials supplies a...
This source does not provide full text. Read it at seclists.org.