Junglewise Threat Intelligence

CVE-2024-22196: 0xJacky Nginx-UI SQL injection in OrderAndPaginate

CVE-2024-22196 · Severity: high · CVSS 7 · Published 2024-01-11

Technologies: 0xJacky Nginx-UI, github.com/0xJacky/Nginx-UI (Go). Vendors: 0xJacky, Go.

Executive brief

Nginx-UI, a web-based management interface for Nginx, is vulnerable to a security flaw that allows authenticated users to execute unauthorized database queries. By manipulating specific web requests used for sorting and paging data, an attacker could gain access to sensitive information stored in the system's database. This could lead to the exposure of configuration details or other private data managed by the application.

Technical details

A SQL injection vulnerability exists in Nginx-UI's `OrderAndPaginate` and `SortOrder` functions within `model/model.go`. The application uses `fmt.Sprintf` to construct SQL ORDER BY clauses using the `sort_by` and `order` query parameters without sufficient sanitization or parameterization. An authenticated attacker can exploit this by sending crafted GET requests to endpoints using these functions (such as `/api/dns_credentials`), using CASE statements or other SQL syntax to perform boolean-based or error-based inference of database contents. The vulnerability was addressed in version 1.9.10-0.20231219195202-ec93ab05a3ec.

Affected products

  • 0xJacky Nginx-UI < 1.9.10-0.20231219195202-ec93ab05a3ec

Timeline

  • 2024-01-11: disclosed
  • 2024-01-11: advisory
  • 2023-12-19: patched: Patch committed to repository

References

Related threats