ZDI-CAN-23950: ZDI-25-852: (0Day) CData API Server MySQL Misconfiguration Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL connections. When connecting to a MySQL server, the product enables an option that gives the MySQL server permission to request local files from the MySQL client. An attacker can leverage this vulnerability to disclose information in the context of NETWORK SERVICE.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2025-9273.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23950?
The severity of ZDI-CAN-23950 is considered to be high due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-23950?
To fix ZDI-CAN-23950, ensure that all MySQL server connections are properly secured, and apply any patches provided by CData.
What types of attacks can ZDI-CAN-23950 facilitate?
ZDI-CAN-23950 can facilitate remote attacks that lead to unauthorized disclosure of sensitive information.
Is authentication required to exploit ZDI-CAN-23950?
Yes, authentication is required to exploit the ZDI-CAN-23950 vulnerability.
Which software is affected by ZDI-CAN-23950?
ZDI-CAN-23950 affects installations of CData API Server that utilize MySQL connections.