Executive brief
The Guardian language-system, a tool used for automatic translation and subtitling, contains a security flaw in how it handles database queries. An attacker can exploit this to gain unauthorized access to the system's database, potentially exposing sensitive information or internal data. This vulnerability allows for the extraction of database contents without requiring complex technical maneuvers.
Technical details
A SQL injection vulnerability exists in the Guardian language-system due to improper neutralization of the 'id' GET parameter in subtitles.php (line 16). The application passes the unsanitized parameter directly into a SQL query: SELECT id, filename, extension, type FROM files where id = '...'. While the advisory description mentions an authenticated attacker, the CVSS vector (PR:N) and associated proof-of-concept materials suggest this may be reachable without authentication or with low-level guest credentials. An attacker can leverage error-based SQL injection techniques (e.g., using GTID_SUBSET) to extract database versions, user information, and table contents. The vulnerability is present in versions up to and including commit e42c395.
Affected products
- Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory