Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g23g-mw97-65c8

Опубликовано: 01 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

IBAX go-ibax vulnerable to SQL injection

SQL Injection vulnerability in /packages/api/database.go of go-ibax via where parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects versions starting from commits on Jul 18, 2020.

Пакеты

Наименование

github.com/IBAX-io/go-ibax

go
Затронутые версииВерсия исправления

< 1.4.2

1.4.2

EPSS

Процентиль: 50%
0.00273
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.3
nvd
больше 3 лет назад

A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212638 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 50%
0.00273
Низкий

8.8 High

CVSS3

Дефекты

CWE-89