Sceawere
Vulnerability Detail
CVE-2026-94663UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ProfileGrid Blind SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.5
- Creation Date
- 3h ago
- Vendor
- Metagauss
- Product
- ProfileGrid
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid: from n/a through 6.0.0.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.5",
"pubDate": "2026-10-09T10:16:41.283Z",
"pubdate": "2026-10-09T10:16:41.283Z",
"executiveSummary": "ProfileGrid, specifically the profilegrid-user-profiles-groups-and-communities plugin, is susceptible to a Blind SQL Injection vulnerability classified under CWE-89: Improper Neutralization of Special Elements used in an SQL Command.\nThe vulnerability exists due to insufficient sanitization of user-supplied input before it is incorporated into database queries, allowing an attacker to manipulate SQL commands remotely.\nThis flaw enables unauthorized database interaction, potentially leading to the extraction of sensitive information such as administrative credentials, user data, or system configurations through blind inference techniques.\nThe impact is significant, as it permits an attacker to perform unauthorized data exfiltration or modify database state without direct access to the database management system.\nThe vulnerability affects all versions of the ProfileGrid plugin from n/a through 6.0.0.2. Successful exploitation typically requires network access to the target application, though it does not inherently require high-level authentication, depending on the specific endpoint exposed to the vulnerable parameter.\nRisk implications include full compromise of application data integrity and confidentiality.",
"technicalDetails": "The core vulnerability is identified as a Blind SQL Injection within the ProfileGrid plugin, spanning versions n/a through 6.0.0.2. This vulnerability occurs when the application dynamically constructs SQL queries by concatenating unsanitized user-supplied input directly into query strings.\nRoot Cause: The application fails to utilize prepared statements or parameterized queries when interacting with the database. Consequently, special SQL characters and syntax provided by an attacker are interpreted as code by the database backend rather than data. This flaw permits the injection of arbitrary SQL fragments into the underlying query execution path.\nExploitation Method: Since the vulnerability is classified as Blind SQL Injection, the application does not return direct database errors or query results in the HTTP response body. Instead, attackers must employ inference-based exploitation techniques. This involves observing differences in application behavior—such as variations in HTTP response time (time-based) or discrepancies in the content of the rendered page (boolean-based)—in response to injected payloads.\nAttack Flow: An attacker identifies an entry point, such as a GET or POST parameter, that the ProfileGrid plugin processes internally. By injecting crafted SQL payloads, the attacker triggers conditional logic within the database. For example, a payload containing a 'WAITFOR DELAY' or 'BENCHMARK()' function allows the attacker to measure the time taken for the server to respond, thereby confirming the existence of the injection point and incrementally exfiltrating data bit-by-bit.\nComponent and Exposure: The vulnerable logic resides within the plugin’s request handling modules. Since these components process user input directly from the web interface, the vulnerability is exposed over the network. Authentication requirements depend on whether the vulnerable endpoint is reachable by unauthenticated users or if it requires a low-privilege user session. Post-exploitation impact is severe, potentially allowing for the dumping of entire database tables, authentication bypass, or unauthorized escalation of privileges if the database user permissions are overly permissive.\nThe absence of robust input validation or parameterized query implementation throughout the vulnerable version range allows attackers to execute arbitrary SQL queries, bypassing typical application-layer security controls."
}