Количество 3
Количество 3
CVE-2026-72558
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
CVE-2026-72558
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows a ...
GHSA-h3jq-rqqh-3gvh
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-72558 An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-72558 An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows a ... | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-h3jq-rqqh-3gvh An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу