Skip to content

Blind SQL injection during the CommentGrade process

High
PierreRambaud published GHSA-5v44-7647-xfw9 Dec 3, 2020

Package

No package listed

Affected versions

>= 4.0.0

Patched versions

4.2.1

Description

Impact

An attacker can use a Blind SQL injection to retrieve data or stop the MySQL service.

Patches

The problem is fixed in 4.2.1

References

SQL Injection (CWE-89)

Vector String

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Severity

High

CVE ID

CVE-2020-26248

Weaknesses

No CWEs

Credits