THREATOPS
THREAT OPSThreat News › Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)

Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)

lowfulldisclosurePublished 2026-08-18

<p>Posted by disclosure via Fulldisclosure on Aug 17</p>0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is <br /> published and a proof-of-concept is available.<br /> <br /> Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)<br /> <br /> Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDE

Original source: https://seclists.org/fulldisclosure/2026/Aug/66