Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Bypass Apache Superset restrictions to perform SQL injections

Summary

Quarkslab bypassed Apache Superset's SQL-injection guards during an audit by leveraging PostgreSQL behavior, achieving injections on two API routes and escalating time-based to error-based.
Published
Collected

original ↗

Related coverage

back