Логотип exploitDog
bind:CVE-2022-23857
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23857

Количество 2

Количество 2

nvd логотип

CVE-2022-23857

около 4 лет назад

model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pmcr-2rhp-36hr

около 4 лет назад

SQL injection in github.com/navidrome/navidrome

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-23857

model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-pmcr-2rhp-36hr

SQL injection in github.com/navidrome/navidrome

0%
Низкий
около 4 лет назад

Уязвимостей на страницу