Sceawere

Vulnerability Detail

CVE-2026-95610UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Blind SQL Injection in UpSolution Core

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
UpSolution
Product
UpSolution Core
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UpSolution UpSolution Core us-core allows Blind SQL Injection.This issue affects UpSolution Core: from n/a through 9.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-10-09T10:16:43.330Z",
  "pubdate": "2026-10-09T10:16:43.330Z",
  "executiveSummary": "The vulnerability identified in UpSolution Core is a Blind SQL Injection (SQLi) flaw categorized under CWE-89: Improper Neutralization of Special Elements used in an SQL Command.\nThis security defect allows an unauthenticated or authenticated attacker to perform unauthorized database operations by injecting malicious SQL fragments into input fields that are improperly sanitized by the application.\nThe vulnerability affects UpSolution Core versions from n/a through 9.3.\nExploitation of this flaw enables an attacker to infer sensitive information from the underlying database—such as user credentials, configuration data, or private site content—by observing time-based delays or boolean-based response variations.\nThe primary risk implication is a significant breach of data confidentiality. Successful exploitation does not require direct access to the database management system but leverages the application's interface to query the database indirectly.\nThe impact is critical, as it bypasses standard application-level access controls and may lead to full database compromise depending on the database user's privileges configured within the web server environment.",
  "technicalDetails": "The root cause of this vulnerability lies in the failure of the UpSolution Core plugin to correctly parameterize or sanitize user-supplied input before incorporating it into dynamic SQL query strings.\nWhen input fields or parameters within the affected versions are processed by the database query logic, special SQL characters (e.g., single quotes, comments, or logical operators) are treated as executable instructions rather than data literals.\nBecause the vulnerability is a 'Blind' SQL Injection, the application does not return direct error messages or database output to the user interface. Instead, attackers must utilize side-channel techniques to exfiltrate data.\nThe exploitation flow typically begins with the attacker identifying a vulnerable parameter within a GET or POST request. By injecting Boolean-based conditions (e.g., 'AND 1=1' vs 'AND 1=0'), the attacker observes differences in the HTTP response body, headers, or status codes to verify the presence of the injection point.\nIf Boolean inference is ineffective, the attacker may employ time-based blind injection techniques. In this scenario, the attacker injects sleep-inducing functions (e.g., SLEEP(), BENCHMARK()) into the query. If the server response delay correlates with the injected command, the attacker confirms successful code execution.\nBy systematically appending subqueries to the original SQL statement, an attacker can iterate through the database character by character. This allows for the extraction of entire table structures, user identities, hashes of passwords, and sensitive configuration keys stored within the plugin's metadata or associated database tables.\nThe vulnerable component resides within the core functionality of the UpSolution Core plugin, specifically in the input validation and query construction modules used for handling user requests.\nThe exploitation process does not necessarily require high-level administrative privileges, as the vulnerable entry points are often exposed to front-end users or public-facing application endpoints.\nPost-exploitation, the attacker may achieve full database reconnaissance, which could lead to further attacks such as privilege escalation, account takeover via credential extraction, or the modification of application data to facilitate arbitrary code execution through additional attack vectors."
}
CVE-2026-95610: Blind SQL Injection in UpSolution Core (HIGH Severity, CVSS: 8.5) | Sceawere