Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Rt-Saber

#32903of 57,635
8.7Total CVSS
Vulnerabilities · 1
PT-2026-99467
8.7
2026-09-27
Azuracast · Azuracast · CVE-2026-100847
**Name of the Vulnerable Software and Affected Versions** AzuraCast versions prior to 0.23.8 **Description** A DQL injection issue exists in the `AbstractSearchableListAction.php` file. An attacker can inject arbitrary DQL (Doctrine Query Language) expressions—an object-oriented query language used by the Doctrine ORM—via the `sortOrder` parameter in the API. This allows for the extraction of sensitive database information, such as station settings and user credentials. **Recommendations** Update to version 0.23.8 or later. As a temporary mitigation, restrict access to the API parameter `sortOrder` within the `AbstractSearchableListAction.php` component.