NG Solution Team
Cybersecurity

GeoServer zero-day: attackers exploit unpatched SQL injection

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.

A bug bounty hunter shared the vulnerability Wednesday on X as a zero day. According to the post, the jsonArrayContains function contains a vulnerability that allows unauthenticated users to inject SQL commands into the database.

GeoServer vulnerability details

The flaw remains unpatched, and security researchers report signs of attempted exploitation. GeoServer is widely used by organizations across many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hackers in the past.

Related posts

Lakelands Public Health reveals scope of data breach — 60,000 affected

James Smith

Are Over 70,000 Fortinet Devices at Risk Due to the FortiBleed Credential Leak?

James Smith

Is there a hidden admin backdoor in Tenda routers allowing unauthorized remote access?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy