PT-2026-79571 · Fabrik · Fabrik
CVE-2026-76571
·
Published
2026-08-22
·
Updated
2026-08-23
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Fabrik versions prior to 4.7.2
Description
An unauthenticated attacker can perform a SQL injection by supplying arbitrary SQL through the
condition parameter passed to a list filter. This occurs because the parameter is concatenated verbatim into the WHERE clause constructed by the getFilterQuery() function, potentially allowing full read access to the database.Recommendations
Update to version 4.7.2 or later.
As a temporary mitigation, restrict access to the list filter functionality that utilizes the
condition parameter.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fabrik