External risk intelligence

Xhibiter NFT Marketplace SQL Injection in Collections Endpoint

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2024-58290

The vulnerability exists in a marketplace application's collections endpoint. NFT marketplaces are web-based applications designed to be publicly accessible over the internet to facilitate trading, browsing, and user interaction, making this a common internet-facing web application deployment.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability involves a widely accessible NFT marketplace platform where attackers can manipulate database queries through a specific parameter. This could allow unauthorized access to or modification of sensitive information.

  • Attackers can inject malicious commands.
  • Confirms exposure of a public-facing marketplace.
  • Understand potential data risks to the platform.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerability by interacting with the publicly accessible collections page of the NFT marketplace. By sending specially crafted input through the 'id' parameter, an attacker can trick the application into executing unintended database commands. This manipulation could allow an attacker to view or alter sensitive data stored within the marketplace's database.

  • No authentication or special access needed.
  • Manipulate 'id' parameter on collections page.
  • Unauthorized database access or modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to manipulate database queries on the collections page by submitting specially crafted input in the 'id' parameter. When supported by the advisory, this could lead to unauthorized access or modification of the marketplace's database content.

  • Database information is at risk.
  • Attackers can inject malicious SQL queries.
  • Database content may be exposed or altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Application Owner and Platform Team are likely responsible for addressing this SQL injection vulnerability. The first practical step is to identify all instances of the Xhibiter NFT Marketplace, confirm their reachability and criticality, and then assign an owner to plan remediation within an appropriate maintenance window.

  • Application owners should lead remediation efforts.
  • Verify marketplace reachability and business criticality.
  • Plan coordinated patching or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Xhibiter NFT Marketplace software?

Xhibiter is a web-based template and platform designed to facilitate the creation, browsing, and trading of non-fungible tokens (NFTs). Because it serves as a digital storefront, it is typically hosted as a public-facing web application that allows users to interact with collections and marketplace data dynamically.

What does CVE-2024-58290 mean?

This CVE identifies a SQL injection vulnerability, categorized as CWE-89. It means the software fails to properly sanitize user input in its database queries. Instead of treating input as simple text, the system accidentally interprets it as part of a command, allowing an attacker to manipulate the database through the application.

How can an attacker trigger this SQL injection?

An attacker triggers this by sending a specially crafted input string into the 'id' parameter on the collections page. Simply viewing the page normally does not trigger the bug; the vulnerability is only activated when an attacker intentionally submits malicious code intended to trick the underlying database.

Is my instance of Xhibiter at risk?

According to Halo Surface Signal, this vulnerability is highly relevant because NFT marketplaces are inherently designed to be internet-facing to support user interaction. If your instance is publicly accessible on the internet, it can be reached by anyone, making it a prime candidate for this type of network-based attack.

What should I do if I run Xhibiter?

Begin by locating all deployments of the software across your infrastructure to determine which are active. Once you have an inventory, verify if they are exposed to the public internet and coordinate with your platform team to assign ownership, assess the business risk, and prioritize a remediation plan.

References