Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrj5-qp7x-rpg6

Опубликовано: 26 июл. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

SQL Injection in marginalia

marginalia < 1.6 is affected by SQL Injection. The impact is an injection of any SQL queries when a user controller argument is added as a component. This issue affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is inputting of SQL to a vulnerable vector (header, http parameter, etc). The fixed version is 1.6.

Пакеты

Наименование

marginalia

rubygems
Затронутые версииВерсия исправления

< 1.6

1.6

EPSS

Процентиль: 51%
0.00282
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.

EPSS

Процентиль: 51%
0.00282
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89