Executive brief
A security vulnerability exists in Crocus v.1.3.44, a software solution from Streamax. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive user information, transaction records, or escalate their privileges within the system. This could lead to a total compromise of the data managed by the application and disrupt business operations.
Technical details
A SQL injection vulnerability exists in Streamax Crocus v.1.3.44 within the RecordStateMapper.xml component. The flaw is specifically an 'order by' injection caused by the use of unsafe '${}' string substitution instead of prepared statements. A remote attacker can exploit this by sending crafted requests to trigger time-based blind SQL injection (e.g., using sleep/delay functions). Successful exploitation allows the attacker to bypass authentication, access data from other databases, and potentially obtain DBA-level permissions on the database server.
Affected products
- Streamax Crocus 1.3.44
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory