Potential GeoServer SQLi Probe for CVE-2023-25157 via OWS CQL_FILTER

Alerts on GET requests to GeoServer OWS with CQL_FILTER containing SQLi-style payload markers and functions.

FreeReviewedSigma · High · v5
Category
webserver
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-06-14
Updated
2026-07-31

What it detects

This rule flags HTTP GET requests to GeoServer OWS endpoints that include a CQL_FILTER parameter containing patterns consistent with SQL injection probing. It matches URL query components indicative of filter/function usage and common injection payload fragments such as UNION/SELECT/WHERE and SQL function encodings. The detection relies on webserver request telemetry including the full request method and query string to correlate these indicators in a single request.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.