A vulnerability was found in PeterMu nodebatis up to 2.1.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 6629ff5b7e3d62ad8319007a54589ec1f62c7c35. It is recommended to upgrade the affected component. VDB-217554 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/PeterMu/nodebatis/commit/6629ff5b7e3d62ad8319007a54589ec1f62c7c35 | Patch |
https://github.com/PeterMu/nodebatis/releases/tag/v2.2.0 | Release Notes |
https://vuldb.com/?ctiid.217554 | Third Party Advisory |
https://vuldb.com/?id.217554 | Third Party Advisory |
https://github.com/PeterMu/nodebatis/commit/6629ff5b7e3d62ad8319007a54589ec1f62c7c35 | Patch |
https://github.com/PeterMu/nodebatis/releases/tag/v2.2.0 | Release Notes |
https://vuldb.com/?ctiid.217554 | Third Party Advisory |
https://vuldb.com/?id.217554 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:03
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.2
v3 : 5.5 |
References | () https://github.com/PeterMu/nodebatis/commit/6629ff5b7e3d62ad8319007a54589ec1f62c7c35 - Patch | |
References | () https://github.com/PeterMu/nodebatis/releases/tag/v2.2.0 - Release Notes | |
References | () https://vuldb.com/?ctiid.217554 - Third Party Advisory | |
References | () https://vuldb.com/?id.217554 - Third Party Advisory |
29 Feb 2024, 01:23
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-01-06 11:15
Updated : 2024-11-21 04:03
NVD link : CVE-2018-25066
Mitre link : CVE-2018-25066
CVE.ORG link : CVE-2018-25066
JSON object : View
Products Affected
nodebatis_project
- nodebatis
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')