Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38533
HistoryDec 20, 2022 - 4:42 a.m.

SQL Injection

2022-12-2004:42:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
laravel
jqgrid
sql injection
eloquentrepositoryabstract
database security

0.002 Low

EPSS

Percentile

54.2%

mgallegos/laravel-jqgrid is vulnerable to SQL injection. The vulnerability exists in the getRows function in EloquentRepositoryAbstract.php because the library directly passes the values added at the end of query sorting to the database, allowing a malicious user to inject and execute arbitrary SQL queries on the system.

0.002 Low

EPSS

Percentile

54.2%

Related for VERACODE:38533