PT-2026-109330 · Jetbrains · Exposed
CVE-2026-108474
·
Published
2026-10-09
·
Updated
2026-10-10
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains Exposed versions prior to 1.5.1
Description
SQL injection is possible because several SQL functions accept raw string arguments that are not escaped or parameterized. This allows crafted input to break out of the query context and execute attacker-controlled SQL, which can lead to data exfiltration or modification. Queries that use bound parameters are not impacted.
Recommendations
Upgrade to version 1.5.1.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exposed