CVE-2025-9273
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-02

Last updated on: 2025-09-04

Assigner: Zero Day Initiative

Description
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL connections. When connecting to a MySQL server, the product enables an option that gives the MySQL server permission to request local files from the MySQL client. An attacker can leverage this vulnerability to disclose information in the context of NETWORK SERVICE. Was ZDI-CAN-23950.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-02
Last Modified
2025-09-04
Generated
2026-05-27
AI Q&A
2025-09-02
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
cdata api_server 3.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in CData API Server involves a misconfiguration in how it handles MySQL connections. Specifically, the server enables an option that allows the MySQL server to request local files from the MySQL client. An authenticated remote attacker can exploit this to disclose sensitive information with the privileges of the NETWORK SERVICE account. [1]


How can this vulnerability impact me? :

If exploited, this vulnerability can lead to unauthorized disclosure of sensitive information from the affected system. Although it requires authentication and only impacts confidentiality (not integrity or availability), the attacker gains access to information with NETWORK SERVICE privileges, which could be leveraged for further attacks or data exposure. [1]


What immediate steps should I take to mitigate this vulnerability?

The primary mitigation recommended is to restrict access and interaction with the affected product to prevent exploitation of the vulnerability. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart