Sceawere
Vulnerability Detail
CVE-2026-100847UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast DQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-27T02:17:23.437Z",
"pubdate": "2026-09-27T02:17:23.437Z",
"executiveSummary": "AzuraCast versions prior to 0.23.8 are susceptible to a critical DQL (Doctrine Query Language) injection vulnerability located within the AbstractSearchableListAction.php component.\nThis vulnerability stems from the improper neutralization of the 'sortOrder' API parameter, which allows an attacker to inject arbitrary DQL expressions into database queries.\nSuccessful exploitation permits unauthorized access to sensitive information stored within the application's backend database, including administrator credentials, user metadata, and configuration settings for radio stations.\nThe vulnerability poses a severe risk to confidentiality, as attackers can perform data exfiltration without requiring elevated privileges if the endpoint is exposed.\nThe impact is significant, potentially leading to full account takeover or unauthorized administrative control over the AzuraCast instance.\nExploitation does not require complex prerequisites other than the ability to interact with the vulnerable API endpoint.",
"technicalDetails": "The root cause of this vulnerability is the failure of the AbstractSearchableListAction.php component to adequately sanitize or parameterize input provided to the 'sortOrder' parameter before it is processed by the Doctrine ORM's query builder.\nIn Doctrine Query Language, query construction relies on string concatenation or improper inclusion of user-supplied data, allowing the input to break out of the intended 'ORDER BY' clause context.\nAn attacker can manipulate the 'sortOrder' parameter to append malicious DQL statements. By leveraging DQL's capabilities, an attacker can construct subqueries or utilize JOIN expressions to traverse the database schema and extract data from unrelated tables.\nThe attack flow begins when an attacker sends a crafted HTTP request to an API endpoint that utilizes AbstractSearchableListAction.php. The application retrieves the 'sortOrder' value from the request input and directly embeds this value into the final DQL query string.\nPayload construction typically involves using SQL/DQL injection techniques such as UNION-based attacks or Boolean-based inference to leak sensitive information. Since DQL abstracts the underlying database, the attacker is limited by the ORM's schema mapping, yet the ability to perform cross-entity queries often provides access to all tables registered within the Doctrine entity manager.\nBecause the query is executed server-side with the privileges of the application's database user, the attacker can extract data from any table accessible to the database service. This includes sensitive credentials stored in the user table and critical configuration data within station-related entities.\nThe lack of input validation or an allow-list for sorting criteria enables this behavior. Unlike standard SQL injection which targets the raw database engine, DQL injection targets the application's abstraction layer, often bypassing basic WAF filters that look for traditional SQL keywords but fail to account for DQL-specific syntax or object-oriented query structures.\nPost-exploitation, an attacker can pivot to full system compromise by obtaining hashed passwords for administrative accounts, which can then be cracked offline or used to gain entry to the administrative dashboard, effectively granting the attacker full control over the radio station management infrastructure."
}