Polaris FT Intellect Core Banking SQL Injection Vulnerability in GroupType Parameter

Vulnerability

A SQL injection vulnerability has been identified in Polaris FT Intellect Core Banking version 9.5. The issue arises in the Interllect Core Search, where input from the groupType parameter in the SCGController endpoint is improperly handled before being incorporated into SQL queries. This flaw allows for SQL injection attacks within an authenticated session.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.

Reproduction

To reproduce this vulnerability, send a request to the SCGController endpoint with a crafted groupType parameter that includes SQL injection payloads. The injected SQL code will be executed by the database, allowing the attacker to manipulate database queries. For example, injecting a payload that uses SQL functions to delay the response can demonstrate the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.