Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3jp-7gj7-h6pr

Опубликовано: 08 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 4.8
CVSS3: 5.3

Описание

records-mover Injection vulnerability

A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes SQL Injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name: 3f8383aa89f45d861ca081e3e9fd2cc9d0b5dfaa. Developers should upgrade the affected component.

Пакеты

Наименование

records-mover

pip
Затронутые версииВерсия исправления

< 1.6.0

1.6.0

EPSS

Процентиль: 6%
0.00024
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 месяца назад

A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name: 3f8383aa89f45d861ca081e3e9fd2cc9d0b5dfaa. You should upgrade the affected component.

EPSS

Процентиль: 6%
0.00024
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-74