{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/nu11secur1ty/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["nu11secur1ty"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Purchase Order Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["oretnom23"],"content_html":"\u003cp\u003ePurchase Order Management System (POMS) version 1.0 is affected by a critical SQL injection vulnerability in its login authentication logic. The vulnerability exists within the 'password' parameter processed by '/purchase_order/classes/Login.php'. An attacker can send a crafted POST request to this endpoint to execute arbitrary SQL sub-queries. The proof-of-concept demonstrates the use of the MySQL 'load_file' function to perform an out-of-band (OOB) DNS lookup, which confirms that the application can be forced to interact with attacker-controlled external infrastructure. This vulnerability poses a significant risk to the integrity and confidentiality of the database connected to the application, as successful exploitation could lead to credential harvesting or database dumping.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies the login endpoint at '/purchase_order/admin/login.php'.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting '/purchase_order/classes/Login.php?f=login'.\u003c/li\u003e\n\u003cli\u003eThe attacker injects a malicious SQL string into the 'password' field.\u003c/li\u003e\n\u003cli\u003eThe payload utilizes the 'load_file' function to reference a UNC path, forcing a DNS request to an external domain.\u003c/li\u003e\n\u003cli\u003eThe application backend processes the request and executes the injected SQL command.\u003c/li\u003e\n\u003cli\u003eThe external OAST server (e.g., OASTify) receives the DNS query, confirming successful injection.\u003c/li\u003e\n\u003cli\u003eThe attacker proceeds to extract sensitive information or bypass authentication mechanisms.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to interact with the underlying MySQL database. This can lead to unauthorized access to system credentials, the theft of sensitive procurement data, or potential further compromise of the web application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImplement input sanitization and parameterization for all user-supplied data in 'classes/Login.php', specifically for the 'username' and 'password' parameters.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect malicious SQL injection patterns in web server logs.\u003c/li\u003e\n\u003cli\u003eBlock outbound DNS requests from the web application server to untrusted or non-whitelisted domains to prevent OOB exfiltration.\u003c/li\u003e\n\u003cli\u003eAudit logs for anomalous activity targeting the '/purchase_order/classes/Login.php' endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T14:11:59Z","date_published":"2026-10-01T14:11:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-poms-sqli/","summary":"Purchase Order Management System (POMS) version 1.0 is vulnerable to unauthenticated SQL injection via the password parameter, allowing for exfiltration or out-of-band communication via the MySQL load_file function.","title":"SQL Injection Vulnerability in Purchase Order Management System (POMS)","url":"https://feed.craftedsignal.io/briefs/2026-10-poms-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Nu11secur1ty","version":"https://jsonfeed.org/version/1.1"}