Deerwms Deer-WMS-2 SQL Injection Vulnerability in User Export Function

Vulnerability

A critical SQL injection vulnerability has been identified in DeerWMS Deer-WMS-2 versions up to 3.3. The issue arises in the user export functionality, specifically within the '/system/user/export' endpoint. The vulnerability is caused by unsanitized user input in the 'params[dataScope]' parameter, allowing attackers to manipulate the SQL query and potentially access sensitive database information or gain control over the server.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database. Additionally, according to the vulnerability's source, successful exploitation could result in complete control over the server.

Reproduction

To reproduce this vulnerability, send a POST request to the '/system/user/export' endpoint with a crafted 'params[dataScope]' parameter. The payload should be designed to exploit the SQL injection flaw, such as by using SQL injection techniques to extract database information.

Added: Jul 25, 2025, 3:17 AM
Updated: Jul 25, 2025, 3:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.