VYPR
Unrated severityNVD Advisory· Published Apr 18, 2023· Updated Feb 5, 2025

Multiple SQL injections in sql/instance.py param_edit method in Archery - GHSL-2022-104

CVE-2023-30605

Description

Archery SQL audit platform contains multiple SQL injection vulnerabilities in the param_edit endpoint allowing attackers to query connected databases.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Archery SQL audit platform contains multiple SQL injection vulnerabilities in the param_edit endpoint allowing attackers to query connected databases.

Vulnerability

Archery v1.9.0 (and possibly earlier versions) contains multiple SQL injection vulnerabilities in the sql/instance.py param_edit endpoint. User-supplied input from the variable_name and variable_value parameters is passed unsanitized to the set_variable and get_variables methods in sql/engines/goinception.py and sql/engines/mysql.py. These methods concatenate the input directly into SQL queries, which are then executed against the connected databases via the query method of each engine [1][2].

Exploitation

An attacker with network access to the Archery web interface and knowledge of a valid instance name (defined in Archery) can send crafted requests to the param_edit endpoint. By injecting malicious SQL into the variable_name or variable_value parameters, the attacker can manipulate the resulting SQL query executed on the target database [1].

Impact

Successful exploitation allows the attacker to execute arbitrary SQL queries on any database connected to Archery. This can lead to unauthorized data disclosure, modification, or deletion, potentially compromising the confidentiality, integrity, and availability of the managed databases [1].

Mitigation

As of the advisory publication date (2023-04-18), no official patched version has been released. The recommended mitigation is to escape user input or use prepared statements when constructing SQL queries in the affected methods. Administrators should monitor the Archery repository for updates and apply any security fixes promptly [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • hhyo/Archeryllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <= 1.9.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.