<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aazuracastazuracast/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 27 Sep 2026 03:05:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aazuracastazuracast/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>AzuraCast DQL Injection Vulnerability in sortOrder Parameter</title><link>https://feed.craftedsignal.io/briefs/2026-09-azuracast-dql-injection/</link><pubDate>Sun, 27 Sep 2026 03:05:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-azuracast-dql-injection/</guid><description>AzuraCast versions prior to 0.23.8 are vulnerable to a DQL injection flaw in the sortOrder API parameter, allowing attackers to exfiltrate sensitive database contents.</description><content:encoded><![CDATA[<p>AzuraCast versions before 0.23.8 are susceptible to a DQL injection vulnerability located within the 'sortOrder' API parameter of the 'AbstractSearchableListAction.php' file. An attacker can exploit this flaw by supplying specially crafted DQL (Doctrine Query Language) expressions via the 'sortOrder' parameter. Successful exploitation permits the attacker to bypass standard query logic, potentially leading to the unauthorized exfiltration of sensitive information from the application's database, including user credentials and station configuration settings. This vulnerability presents a significant risk to the integrity and confidentiality of the AzuraCast environment. Organizations should prioritize updating to version 0.23.8 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized actors to query and extract sensitive database contents. This could lead to the exposure of administrative user credentials and specific stream/station configuration data, potentially facilitating full application compromise or unauthorized control over broadcast settings.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all AzuraCast instances to version 0.23.8 or later immediately to patch CVE-2026-100847. Detection engineering teams should monitor web access logs for anomalous, high-entropy content or SQL/DQL-like syntax (e.g., SELECT, FROM, JOIN, WHERE) within the 'sortOrder' query parameter of API requests.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>web-application</category><category>vulnerability</category><category>webserver</category><category>broken-access-control</category><category>api-security</category><category>credential-exposure</category><category>web-vulnerability</category><category>code-injection</category><category>rce</category></item></channel></rss>