A critical SQL injection vulnerability was discovered in the Orkes Conductor platform (version 5.2.4, platform v1.19.12), allowing authenticated attackers to exploit the sort parameter in the /api/workflow/search endpoint. By injecting crafted SQL expressions, attackers can perform time-based blind SQL injection attacks against the backend PostgreSQL database, bypassing basic input filtering. Proof-of-concept payloads demonstrated the ability to induce measurable delays in server response, confirming the vulnerability and enabling potential data exfiltration through timing-based inference.
In addition to this real-world vulnerability, practical labs demonstrate exploitation techniques for blind SQL injection, including out-of-band data exfiltration and conditional error-based methods. These labs guide users through leveraging tracking cookies to inject payloads, using tools like Burp Suite and custom Python scripts to extract sensitive information such as administrator passwords from vulnerable databases. The combination of real-world disclosure and hands-on labs highlights the ongoing risk posed by blind SQL injection flaws and the importance of robust input validation and monitoring in web applications.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A second lab write-up demonstrated exploiting a tracking-cookie blind SQL injection flaw to trigger out-of-band DNS or HTTP interactions to an external server. The method enabled asynchronous exfiltration of the administrator password from the database without changing the application's normal response.
LevelBlue SpiderLabs published a report disclosing an SQL injection vulnerability in Orkes Conductor and assigned it CVE-2025-66387. The reference indicates public technical disclosure of the issue, but provides no additional remediation or exploitation details in the supplied content.
A PortSwigger-style lab write-up showed how a tracking cookie used for analytics could be exploited for blind SQL injection by triggering database errors conditionally. The technique was used to infer and extract the administrator password from a users table despite no direct query output being returned.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcelevelblue.com
Open sourceosintteam.blog
Open sourceblog.silentsignal.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.