SQL injection in geotools - CVE-2023-25158
Published: February 21, 2023 / Updated: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in the OGC Filter handling in org.geotools.jdbc when processing user-supplied filter input. A remote attacker can send a specially crafted filter expression to execute arbitrary SQL commands.