Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6m4-34cj-4hh7

Опубликовано: 21 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

MindSQL is vulnerable to Code Injection through its ask_db function

A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing a manipulation results in code injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Пакеты

Наименование

mindsql

pip
Затронутые версииВерсия исправления

<= 0.2.1

Отсутствует

EPSS

Процентиль: 14%
0.00046
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.3
nvd
20 дней назад

A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing a manipulation results in code injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 14%
0.00046
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74