Bypass Apache Superset restrictions to perform SQL injections
blog.quarkslab.com | research | #sql-injection | #postgresql | #vulnerability | #pentest | #apache-superset | #bypass
Summary
Quarkslab bypassed Apache Superset's SQL-injection guards during an audit by leveraging PostgreSQL behavior, achieving injections on two API routes and escalating time-based to error-based.
- Published
- Collected
Skip to content