CVE-2023-25157 is a SQL injection vulnerability in GeoServer affecting database-backed geospatial services that use OGC Filter expressions and the OGC Common Query Language through WFS, WMS, and, for ImageMosaic coverages, WCS. The flaw is associated with unsafe handling of user-controlled filter input in GeoServer and its PostGIS-backed query generation paths, including misuse scenarios involving functions such as strEndsWith, strStartsWith, PropertyIsLike, and FeatureId processing. In vulnerable configurations, crafted requests can cause untrusted input to be incorporated into SQL statements sent to the backend database. The issue was addressed in GeoServer 2.21.4 and 2.22.2 and was described as related to a regression of another GeoServer SQL injection issue, CVE-2023-25158.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a Docker Compose-based local training lab and operational PowerShell proof-of-concept suite for GeoServer/GeoTools OGC Filter SQL injection vulnerabilities CVE-2023-25157 and CVE-2023-25158. The main exploit automation is attack-chain.ps1, supported by shared HTTP helpers in lab-common.ps1 and shorter differential PoCs for each CVE. It sends unauthenticated WFS 1.1.0 GetCapabilities, DescribeFeatureType, and GetFeature requests to the exposed gateway, then exercises CQL_FILTER function and text FeatureId injection paths. Evidence files preserve the generated request URLs and responses from a successful run. The lab builds vulnerable GeoServer 2.22.0/GeoTools 28.0, patched GeoServer 2.22.2/GeoTools 28.2, two mitigation configurations, and an optional deliberately over-privileged worst-case configuration. OpenResty exposes only 127.0.0.1:8889 and maps distinct paths to each profile; GeoServer and PostGIS are segregated into Docker networks and are not host-published. The realistic route strips SQL errors but does not prevent the demonstrated result-count boolean oracle. The repository additionally contains SQL database seeding and privilege models, a non-JDBC shapefile negative control, setup/validation scripts, gateway configuration, a Vietnamese exploit guide/report, and report-generation assets. The standard attack chain is constrained to lab canaries and read-only data extraction: it demonstrates that least privilege blocks access to internal_assets, whereas the geoserver_impact role permits canary disclosure. The optional worst-case script is separate and reads only the mounted /lab/flag.txt lab canary.
This repository is a vulnerable lab and proof-of-concept documentation set for GeoServer/GeoTools SQL injection vulnerabilities CVE-2023-25157 and CVE-2023-25158. It is not an automated exploit tool; instead, it provides a reproducible Docker environment plus detailed exploitation guidance showing how malicious WFS filter input is translated into unsafe SQL against PostgreSQL/PostGIS. Repository structure: README.md gives the overview and startup instructions; REPORT.md is the main technical write-up describing four tested attack vectors and sample HTTP requests/SQL behavior; docker-compose.yml launches a two-container lab (GeoServer 2.22.1 and PostGIS/PostgreSQL 13-3.1); init.sql creates sample spatial tables and seed data; startup.sh auto-configures GeoServer through its REST API, creating a workspace, vulnerable PostGIS datastore, and two published feature types. Main exploit capabilities: the PoC demonstrates unauthenticated or weakly protected web exploitation over GeoServer WFS endpoints using crafted CQL_FILTER or OGC XML Filter input. The documented vectors include strStartsWith, strEndsWith, PropertyIsLike, and FeatureId-based injection. The goal is error-based SQL injection: attacker-controlled input breaks out of generated SQL string context, appends SQL such as a CAST(version()) expression, and causes PostgreSQL to return an error containing backend version information. This proves arbitrary SQL expression injection in the query path, though the repository stops at information disclosure and does not include automation, shells, or persistence payloads. Notable targeting details: the lab intentionally enables vulnerable datastore settings in startup.sh, especially 'encode functions=true' and 'preparedStatements=false', and exposes primary keys. The FeatureId vector specifically depends on a string primary key table (example_str). The exploit surface is GeoServer's HTTP/WFS interface, while the backend target is PostgreSQL/PostGIS. Overall maturity is best classified as POC because the repository is a lab and report with manual payloads rather than a weaponized exploit implementation.
This repository contains a proof-of-concept (POC) exploit for a SQL injection vulnerability in GeoServer versions prior to 2.18.7, 2.19.7, 2.20.7, 2.21.4, and 2.22.2. The vulnerability arises from improper filtering of user input in the CQL_FILTER parameter, allowing remote, unauthenticated attackers to inject SQL via crafted HTTP requests. The main exploit script, exp.py, is written in Python and automates the process of: 1. Enumerating available FeatureTypes from the target GeoServer instance using the /geoserver/ows endpoint. 2. For each FeatureType, retrieving its properties via the /geoserver/wfs endpoint. 3. Attempting SQL injection on each property by sending a specially crafted CQL_FILTER parameter in a GetFeature request, aiming to extract database information (such as the version). The script supports both single and multiple target URLs, uses multi-threading for efficiency, and provides colored output for result clarity. The README.md provides a detailed description of the vulnerability, affected versions, and example payloads. No hardcoded IPs or domains are present; the script is designed to be run against user-supplied targets. The exploit demonstrates the vulnerability by extracting database information, confirming the presence of the SQL injection flaw.
This repository is a proof-of-concept (POC) exploit for a SQL injection vulnerability in GeoServer 2.22.1. The repository contains three files: a docker-compose.yml for setting up a vulnerable GeoServer and PostGIS environment, a startup.sh script to initialize the GeoServer instance with the required workspace and datastore, and poc.py, a Python script that performs the actual exploit. The exploit targets the /geoserver/ows endpoint, sending a specially crafted CQL_FILTER parameter in a WFS GetFeature request to attempt SQL injection and extract database version information. The setup scripts ensure the environment is ready for exploitation, making this a self-contained POC for demonstrating the vulnerability.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-25157, a critical SQL injection vulnerability in GeoServer's OGC Filter implementation. The main file, CVE-2023-25157.py, is a Python script that automates the exploitation process. It first enumerates available feature types and their properties from a target GeoServer instance by sending crafted HTTP requests to the /geoserver/ows endpoint. It then attempts to exploit the SQL injection vulnerability by injecting a payload into the CQL_FILTER parameter of a GetFeature request, aiming to extract the database version as a demonstration. The script is intended for educational and research purposes, as stated in the README.md, and requires the user to supply the base URL of the target GeoServer. The attack vector is network-based, targeting HTTP endpoints exposed by GeoServer. The repository is structured simply, with one Python exploit script and a detailed README explaining usage, context, and legal disclaimers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.