Security Advisory

CVE-2025-51535Unrestricted SQL console in the admin UI

OpenAtlas · Austrian Academy of Sciences (ÖAW)

CVE published 4 Aug 2025 · discovered 19 May 2025

Overview

OpenAtlas 8.11.0 exposed an SQL console in its administrative interface, allowing privileged users to execute broad database commands. Public CVE databases classify the finding as SQL injection, whereas my original report concerned the unrestricted SQL function in the admin UI.

Technical findings

The terminology matters in this case. What I observed was an admin SQL console that permitted direct, extensive SQL execution.

If a privileged application account is compromised, this functionality can give the attacker direct access to the database layer. Depending on permissions, data confidentiality, integrity and availability may be affected.

Public CVE databases list this as SQL injection, and the CISA/NVD classification subsequently changed. I therefore distinguish the observed behavior from external taxonomy.

Why it matters

Using this function directly requires high application privileges. But if such an account is compromised, the SQL console can greatly increase the damage because database operations are no longer constrained by the application’s normal features.

Potential impact

  • Arbitrary SQL statements can be executed from the admin UI, posing a substantial risk to data integrity and availability.

Remediation

  • Upgrade to OpenAtlas 8.12.0 or later.
  • Remove generic SQL execution from production web interfaces.
  • Limit the web application’s database accounts to strictly necessary operations.
  • Apply separate protections to administrative functions and maintain auditable logs of database and schema changes.

Affected and fixed versions

Affected<= 8.11.0
Fixed / vendor-confirmed8.12.0

References

Related OpenAtlas research