RSI Queue Management System Unauthenticated Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability allowing unauthenticated attackers to inject time-delayed SQL payloads has been identified in RSI Queue Management System version 3.0. The vulnerability resides within the TaskID parameter of the GET request handler. Exploitation of this issue enables attackers to induce server response delays, facilitating time-based inference and iterative extraction of sensitive database information without the need for authentication.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive database contents through iterative extraction methods, taking advantage of the time-based SQL injection technique.

Reproduction

To reproduce this vulnerability, send a GET request with a malicious payload injected into the TaskID parameter. The injected SQL payload should be crafted to include time delays, such as using SQL commands that pause execution. The server's response time will indicate whether the injected payload was successful, allowing for boolean-based inference. This process can be repeated to extract database information iteratively.

Remediation

Users are advised to update to the patched version of RSI Queue Management System, which is available as of May 2, 2025.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.