Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93r3-3845-hqh2

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify database information.

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify database information.

EPSS

Процентиль: 14%
0.00045
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.1
nvd
23 дня назад

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify database information.

EPSS

Процентиль: 14%
0.00045
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89