CVE-2024-55586

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.
Configurations

No configuration.

History

12 Dec 2024, 02:08

Type Values Removed Values Added
Summary (en) Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. (en) Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.

11 Dec 2024, 16:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Nette Database hasta la versión 3.2.4 permite la inyección SQL en ciertas situaciones que involucran un filtro no confiable que se pasa directamente al método where.

10 Dec 2024, 14:30

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 14:30

Updated : 2024-12-12 02:08


NVD link : CVE-2024-55586

Mitre link : CVE-2024-55586

CVE.ORG link : CVE-2024-55586


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')