Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-25157 — Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes. | Kitploit
Tools/GitHubGitHub/ivanesk315/cve-2023-25157
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationDatabase SecurityLabs & Practice
GitHubivanesk315/cve-2023-25157

CVE-2023-25157

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

1921 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Content not available in the requested language. Showing English version.

Lab CVE-2023-25157 va CVE-2023-25158

Lab nay dung GeoServer/PostGIS de nghien cuu OGC Filter SQL injection trong moi truong cuc bo, co tach ro operator/setup mode va attacker mode.

  • CVE-2023-25157: be mat GeoServer product, request WFS/WMS di vao JDBC filter encoding.
  • CVE-2023-25158: root cause o GeoTools JDBC library, duoc GeoServer nhung de bien OGC filter thanh SQL.

GeoServer 2.22.0 nhung GeoTools vulnerable. GeoServer 2.22.2 nhung GeoTools patched. Lab giu cung schema/request de A/B test version, mitigation va privilege boundary.

Kien truc

ModeSurfaceMuc dich
Setup/operator RESTcve-operator internal containerREST setup, validation and backend log review
Single gateway127.0.0.1:8889Mot port duy nhat cho UI operator va cac OWS route
Operator Web UI127.0.0.1:8889/geoserver/web/GeoServer UI cho nguoi van hanh; co Basic Auth proxy
Attacker vulnerable127.0.0.1:8889/vuln/geoserver/owsWFS/OWS vulnerable, loi DB hien trong response
Attacker patched127.0.0.1:8889/patched/geoserver/owsGeoServer 2.22.2 / GeoTools 28.2
Attacker realistic127.0.0.1:8889/realistic/geoserver/owsWFS/OWS vulnerable nhung gateway strip error detail
Mitigation function127.0.0.1:8889/mit-functions/geoserver/owsGeoServer 2.22.0, encode functions=false
Mitigation FeatureId127.0.0.1:8889/mit-featureid/geoserver/owsGeoServer 2.22.0, preparedStatements=true

PostgreSQL/PostGIS khong publish port ra host. GeoServer khong publish truc tiep port 8080 ra host; host chi thay cve-gateway tren 127.0.0.1:8889. Container cve-attacker chi o attacker-net; no khong co route toi PostgreSQL hoac GeoServer internal service. REST setup di qua container noi bo cve-operator tren geoserver-net.

Web UI operator

Mo tren browser:

http://127.0.0.1:8889/geoserver/web/

Dang nhap 2 lop:

  1. Proxy operator Basic Auth: operator / operator_lab
  2. GeoServer UI: admin / geoserver

Tat ca di qua cung mot gateway 8889, khong can nho nhieu port. Burp co the giu proxy mac dinh 127.0.0.1:8080.

Chay lab

.\lab.ps1 reset all
.\lab.ps1 validate
powershell -ExecutionPolicy Bypass -File .\verify-lab.ps1
powershell -ExecutionPolicy Bypass -File .\negative-controls.ps1
powershell -ExecutionPolicy Bypass -File .\attack-chain.ps1

Lenh quan ly:

.\lab.ps1 start vulnerable
.\lab.ps1 start patched
.\lab.ps1 start mitigated
.\lab.ps1 start worstcase
.\lab.ps1 reset all
.\lab.ps1 stop
.\lab.ps1 status

Data va role

Bang seed:

  • cities: integer primary key, cot name text, dung cho strStartsWith/strEndsWith.
  • sensors_text: text primary key, dung cho FeatureId injection.
  • sensors_int: integer primary key, negative control cho FeatureId.
  • events: JSONB research layer.
  • internal_assets: khong publish, chua LAB-CANARY-<UUID> moi sau moi lan reset.
  • local_points: shapefile non-JDBC negative control.

Role:

  • geoserver_readonly: CONNECT, USAGE schema, SELECT chi tren bang publish.
  • geoserver_impact: SELECT them internal_assets de minh hoa app DB user qua rong quyen.
  • geoserver_worstcase: profile rieng, co pg_read_server_files de doc file canary gia /lab/flag.txt.

Flow attack-chain

attack-chain.ps1 thuc hien:

  1. Recon WFS GetCapabilities.
  2. Enum schema DescribeFeatureType.
  3. Baseline va negative requests.
  4. Boolean TRUE/FALSE oracle tren realistic proxy.
  5. Xac nhan CVE-2023-25157 voi vulnerable, patched va encode functions=false.
  6. Xac nhan CVE-2023-25158 voi vulnerable, patched va preparedStatements=true.
  7. Negative controls: integer PK va non-JDBC shapefile.
  8. Leak DB user va discover hidden table qua impact branch.
  9. Chung minh least-privilege chan internal_assets, impact branch leak canary, patched/realistic khong disclose canary.

Evidence duoc luu vao evidence/attack-chain-*. Folder hien tai chi giu lai evidence pass moi nhat de tranh bi roi.

Worst-case profile

Profile nay khong nam trong kich ban chinh:

.\lab.ps1 start worstcase
powershell -ExecutionPolicy Bypass -File .\worstcase-demo.ps1

No chi doc file canary gia /lab/flag.txt, khong doc /etc/passwd, khong dump hash, khong crack password.

Nguon chinh thuc

  • GeoServer advisory: https://github.com/geoserver/geoserver/security/advisories/GHSA-7g5f-wrx8-5ccf
  • GeoTools advisory: https://github.com/geotools/geotools/security/advisories/GHSA-99c3-qc2q-p94m
  • GeoServer statement: https://geoserver.org/vulnerability/2023/02/20/ogc-filter-injection.html
  • NVD CVE-2023-25157: https://nvd.nist.gov/vuln/detail/CVE-2023-25157
  • NVD CVE-2023-25158: https://nvd.nist.gov/vuln/detail/CVE-2023-25158
Download Tool