Visualização normal

Antes de ontemStream principal

LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387

18 de Dezembro de 2025, 12:46

LevelBlue SpiderLabs has discovered a vulnerability in the Orkes Conductor platform (version 5.2.4 | v1.19.12) that allows authenticated attackers to perform time-based blind SQL injection attacks against the backend PostgreSQL database.

LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387

18 de Dezembro de 2025, 12:46

LevelBlue SpiderLabs has discovered a vulnerability in the Orkes Conductor platform (version 5.2.4 | v1.19.12) that allows authenticated attackers to perform time-based blind SQL injection attacks against the backend PostgreSQL database.

❌
❌