Executive brief
The Guardian language-system, a tool used for automated translation and subtitling, contains a security flaw in its media management component. By sending a specially crafted web request, an attacker can gain unauthorized access to the underlying database. This could lead to the theft of sensitive information, including user credentials and private media metadata.
Technical details
A SQL injection vulnerability exists in the Guardian language-system due to improper sanitization of the 'id' GET parameter in 'media.php'. The application passes this parameter directly into a mysqli_query call on line 17. While some documentation suggests authentication is required, the CVSS vector and secondary analysis indicate this can be exploited over the network without prior authentication. An attacker can use error-based SQL injection techniques (such as using GTID_SUBSET) to extract sensitive data from the database, including version information, user tables, and file metadata. The vulnerability is present in versions up to and including git commit e42c395.
Affected products
- Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed: Researcher disclosure by philopentest
- 2026-07-01: advisory: NVD and VulnCheck advisories published