关键信息 1. 漏洞类型 Blind SQL Injection 2. 影响版本 Package Admin API backend Version 0.x.x prior to 0.5.3 3. 影响 Accessing sensitive data Stealing cookies (Admin session, cross version) Tampering user records, roles, and permissions Steal or modify sensitive application data Gain full control over your infrastructure 4. Proof of Concept (Time-Based) Example payload: Normal response: ~500ms With payload: ~5s delay 5. 根因 Incorrect usage of string interpolation in the query construction 6. 推荐修复 Use parameterized queries Whitelist input Use ORM mapping helpers Adopt security middleware 7. 披露政策 CyberDuck Vulnerability Disclosure Policy 8. 相关人员 Shivam Joshi (@zim96) Contributors with your reference questions Submitters who helped find the above account and bug bounty hunters