{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asqlpadsqlpad/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sqlpad:sqlpad:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2022-0944"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SQLPad (\u003c 6.10.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SQLPad"],"content_html":"\u003cp\u003eCVE-2022-0944 is a critical vulnerability identified in SQLPad versions 6.10.0 and earlier, stemming from improper input handling during template processing. An authenticated attacker possessing administrative privileges can trigger a blind template injection by supplying a malicious payload to the /api/test-connection endpoint. Because SQLPad processes this input improperly, it results in remote code execution (RCE) on the underlying host operating system. Given the availability of multiple proof-of-concept exploits on public repositories as of August 2026, the risk of exploitation is elevated for any internet-facing or improperly segmented instances of SQLPad. Defenders should prioritize patching to version 6.10.1 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains authenticated access to the SQLPad management console using valid administrator credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the /api/test-connection endpoint, typically used to verify database connectivity.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious request body containing a template injection payload designed to interact with the server's shell.\u003c/li\u003e\n\u003cli\u003eThe request is sent to the target server via an HTTP POST request.\u003c/li\u003e\n\u003cli\u003eThe application parses the malicious payload in the request body, triggering the template injection vulnerability.\u003c/li\u003e\n\u003cli\u003eThe server-side template engine executes the embedded shell commands (e.g., executing system binaries).\u003c/li\u003e\n\u003cli\u003eThe command execution results in the attacker achieving unauthorized control over the server environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete compromise of the SQLPad application server. Depending on the container or host configuration, this may result in full system-level access, exfiltration of stored database credentials, lateral movement within the network, or deployment of additional malicious payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch all instances of SQLPad to version 6.10.1 or later.\u003c/li\u003e\n\u003cli\u003eRestrict access to the SQLPad web interface and API endpoints using network segmentation or firewall rules, ensuring they are not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to /api/test-connection that contain suspicious characters or strings indicative of template injection (e.g., shell metacharacters like backticks, pipes, or semicolons).\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring for unexpected process creation originating from the SQLPad application service account or container.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T08:24:27Z","date_published":"2026-08-28T08:24:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-0944/","summary":"SQLPad versions prior to 6.10.1 contain a blind template injection vulnerability (CVE-2022-0944) allowing authenticated high-privileged users to execute arbitrary system commands via the /api/test-connection endpoint.","title":"Remote Code Execution via Blind Template Injection in SQLPad","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-0944/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sqlpad:sqlpad:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}