ZDI-25-852: (0Day) CData API Server MySQL Misconfiguration Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL connections. When connecting to a MySQL server, the product enables an option that gives the MySQL server permission to request local files from the MySQL client. An attacker can leverage this vulnerability to disclose information in the context of NETWORK SERVICE.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2025-9273.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-852?
The severity of ZDI-25-852 is considered significant due to the potential for sensitive information disclosure by authenticated attackers.
How do I fix ZDI-25-852?
To fix ZDI-25-852, it is recommended to update to the latest version of CData API Server where the vulnerability has been addressed.
Who is affected by ZDI-25-852?
ZDI-25-852 affects installations of CData API Server that utilize MySQL connections.
Is authentication required to exploit ZDI-25-852?
Yes, authentication is required to exploit the vulnerability identified in ZDI-25-852.
What type of information can be disclosed through ZDI-25-852?
ZDI-25-852 can potentially disclose sensitive information from affected installations of CData API Server.