Security Research

CVE-2023-25157 GeoServer SQLi: Property Injection in OGC API Filters

#Vulnerability Analysis#Code Audit#Web Security
Copper-orange OGC filter string passing a SQL injection payload

GeoServer’s WFS/WMS GetFeature requests accept OGC Filter parameters — but the property name field has zero SQL escape, and attackers can splice arbitrary SQL subqueries straight into it to harvest the entire database.

Unlock to view this content.