Description
PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Data Access SQL Injection (4.3.1)
IBM WebSEAL Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-1803)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29209)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (2.3)