Overview
OpenAtlas 8.11.0 exposed an SQL console in its administrative interface, allowing privileged users to execute broad database commands. Public CVE databases classify the finding as SQL injection, whereas my original report concerned the unrestricted SQL function in the admin UI.
Technical findings
The terminology matters in this case. What I observed was an admin SQL console that permitted direct, extensive SQL execution.
If a privileged application account is compromised, this functionality can give the attacker direct access to the database layer. Depending on permissions, data confidentiality, integrity and availability may be affected.
Public CVE databases list this as SQL injection, and the CISA/NVD classification subsequently changed. I therefore distinguish the observed behavior from external taxonomy.
Why it matters
Using this function directly requires high application privileges. But if such an account is compromised, the SQL console can greatly increase the damage because database operations are no longer constrained by the application’s normal features.
Potential impact
- Arbitrary SQL statements can be executed from the admin UI, posing a substantial risk to data integrity and availability.
Remediation
- Upgrade to OpenAtlas 8.12.0 or later.
- Remove generic SQL execution from production web interfaces.
- Limit the web application’s database accounts to strictly necessary operations.
- Apply separate protections to administrative functions and maintain auditable logs of database and schema changes.