PT-2022-24988 · Unknown · Matrix-Appservice-Irc

·

CVE-2022-3971

·

Published

2022-11-13

·

Updated

2022-11-17

CVSS v3.1

4.6

Medium

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions matrix-appservice-irc versions up to 0.35.1
Description A critical issue affects the file src/datastore/postgres/PgDataStore.ts, where the manipulation of the roomIds argument leads to sql injection. Upgrading to version 0.36.0 addresses this issue.
Recommendations For matrix-appservice-irc versions up to 0.35.1, upgrade to version 0.36.0 to address the issue. As a temporary workaround, consider restricting the manipulation of the roomIds argument to minimize the risk of sql injection.

Exploit

Fix

Improper Neutralization

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3971
GHSA-FFWF-47X2-JPR8

Affected Products

Matrix-Appservice-Irc