<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nu11secur1ty - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/nu11secur1ty/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 14:11:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/nu11secur1ty/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Purchase Order Management System (POMS)</title><link>https://feed.craftedsignal.io/briefs/2026-10-poms-sqli/</link><pubDate>Thu, 01 Oct 2026 14:11:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-poms-sqli/</guid><description>Purchase Order Management System (POMS) version 1.0 is vulnerable to unauthenticated SQL injection via the password parameter, allowing for exfiltration or out-of-band communication via the MySQL load_file function.</description><content:encoded><![CDATA[<p>Purchase Order Management System (POMS) version 1.0 is affected by a critical SQL injection vulnerability in its login authentication logic. The vulnerability exists within the 'password' parameter processed by '/purchase_order/classes/Login.php'. An attacker can send a crafted POST request to this endpoint to execute arbitrary SQL sub-queries. The proof-of-concept demonstrates the use of the MySQL 'load_file' function to perform an out-of-band (OOB) DNS lookup, which confirms that the application can be forced to interact with attacker-controlled external infrastructure. This vulnerability poses a significant risk to the integrity and confidentiality of the database connected to the application, as successful exploitation could lead to credential harvesting or database dumping.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies the login endpoint at '/purchase_order/admin/login.php'.</li>
<li>The attacker crafts an HTTP POST request targeting '/purchase_order/classes/Login.php?f=login'.</li>
<li>The attacker injects a malicious SQL string into the 'password' field.</li>
<li>The payload utilizes the 'load_file' function to reference a UNC path, forcing a DNS request to an external domain.</li>
<li>The application backend processes the request and executes the injected SQL command.</li>
<li>The external OAST server (e.g., OASTify) receives the DNS query, confirming successful injection.</li>
<li>The attacker proceeds to extract sensitive information or bypass authentication mechanisms.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to interact with the underlying MySQL database. This can lead to unauthorized access to system credentials, the theft of sensitive procurement data, or potential further compromise of the web application environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Implement input sanitization and parameterization for all user-supplied data in 'classes/Login.php', specifically for the 'username' and 'password' parameters.</li>
<li>Deploy the provided Sigma rule to detect malicious SQL injection patterns in web server logs.</li>
<li>Block outbound DNS requests from the web application server to untrusted or non-whitelisted domains to prevent OOB exfiltration.</li>
<li>Audit logs for anomalous activity targeting the '/purchase_order/classes/Login.php' endpoint.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>