Learn-SecByte-CMS-CVE-Shell-to-Root-Privilege-Escalation-CTF-Labs
Author
sifatnotes
Published
2026-09-28
Stars
0
Forks
0
Description
Hands-on cybersecurity and CTF labs covering port reconnaissance, CMS stack discovery, VulnCMS, CVE-2026-58225, shell-to-root paths, Python, sudo, user switching, passwords, and post-exploitation.
CVE-CVE-2026-58225 Details
Severity
UNKNOWN
CVSS Score
0.0
CWE
CWE-89
Description
SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so the name is safe inside a double-quoted identifier. This protects the single-statement LISTEN and UNLISTEN paths. On every (re)connect, however, handle_connect/1 replays all registe...
Related PoCs for CVE-2026-58225
No other PoCs found for this CVE.