Lucene search

K
githubGitHub Advisory DatabaseGHSA-3FHJ-WPVJ-X5W8
HistoryDec 19, 2022 - 3:30 p.m.

laravel-jqgrid vulnerable to SQL Injection

2022-12-1915:30:29
CWE-89
GitHub Advisory Database
github.com
18
laravel-jqgrid
sql injection
eloquentrepositoryabstract.php
getrows function
patch
vulnerability
identifier vdb-216271
fbc2d94f43d0dc772767a5bdb2681133036f935e

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

54.7%

A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.

Affected configurations

Vulners
Node
mgallegoslaravel-jqgridRange1.3.0
VendorProductVersionCPE
mgallegoslaravel-jqgrid*cpe:2.3:a:mgallegos:laravel-jqgrid:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

54.7%

Related for GHSA-3FHJ-WPVJ-X5W8