PT-2023-10339 · Unknown · Liftkit Database

CVE-2016-15020

·

Publicado

2023-01-16

·

Atualizado

2024-05-17

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liftkit database versions up to 2.13.1
Description A critical issue has been found, affecting the function processOrderBy of the file src/Query/Query.php. This leads to sql injection.
Recommendations For liftkit database versions up to 2.13.1, upgrade to version 2.13.2 to address this issue.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-15020
GHSA-8HCF-2M4V-F2RQ

Produtos afetados

Liftkit Database