Executive brief
STER, a software suite used for occupational health and safety management, contains a security vulnerability in its search filters. An authorized user could exploit this flaw to bypass security controls and view sensitive information, including data belonging to other users or internal system records. This could lead to unauthorized data exposure and potential disruption of safety management operations.
Technical details
A SQL injection vulnerability (CWE-89) exists in the STER software due to improper neutralization of user-supplied input within multiple Search Filters. An authenticated attacker with network access can inject malicious SQL commands to query the underlying database. Successful exploitation allows the attacker to retrieve sensitive information, including data belonging to other users or any other data the application's database account has permissions to access. The vulnerability is resolved in version 9.5.
Affected products
- Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy (CIOP-PIB) STER All versions prior to 9.5
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
- 2026-05-22: patched: Fixed in version 9.5