CVE-2021-47714
EUVD-2021-3474522.12.2025, 22:15
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hasura | graphql_engine | 1.3.3 |
𝑥
= Vulnerable software versions