Junglewise Threat Intelligence

CVE-2023-49440: AhnLab EPP SQL injection in preview parameter

CVE-2023-49440 · Severity: high · CVSS 8.8 · Published 2025-10-27

Executive brief

AhnLab EPP Management, a platform used by enterprises to centrally manage endpoint security and malware detection, contains a security flaw in its web administration interface. An attacker with low-level access can manipulate database queries to gain full control over the backend database. This could lead to the theft of sensitive security data, unauthorized modification of security policies, or limited remote control over the management server.

Technical details

A Boolean-based and time-based SQL injection vulnerability exists in the web admin interface of AhnLab EPP Management. The flaw is located in the 'preview' parameter within JSON payloads sent to the '/api/console/ems/query/report/preview' endpoint. An authenticated attacker with low privileges can exploit this to execute arbitrary SQL commands with administrative rights on the backend database. Successful exploitation can lead to full database compromise and, in some configurations, limited remote code execution (RCE). The issue was addressed in versions released after 1.0.15.

Affected products

  • AhnLab EPP Management (Endpoint Protection Platform) 1.0.15 and earlier

Timeline

  • 2023-07-16: other: Vulnerability discovered/reported by researcher
  • 2023: patched: Fixes applied in releases following v1.0.15
  • 2025-10-27: advisory: CVE published to NVD

References

Related threats