A weakness has been identified in Korzh EasyQuery up to 7...
Moderate severity
Unreviewed
Published
Sep 14, 2025
to the GitHub Advisory Database
•
Updated Sep 14, 2025
Description
Published by the National Vulnerability Database
Sep 14, 2025
Published to the GitHub Advisory Database
Sep 14, 2025
Last updated
Sep 14, 2025
A weakness has been identified in Korzh EasyQuery up to 7.4.0. This issue affects some unknown processing of the file /api/easyquery/models/nwind/fetch of the component Query Builder UI. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
References