Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5444
HistoryNov 17, 2017 - 3:48 a.m.

SQL Injection

2017-11-1703:48:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

51.6%

contao/core is vulnerable to SQL Injection attacks. The library does not properly sanitize the search filter in the backend, allowing a malicious user to inject and execute arbitrary SQL commands.

CPENameOperatorVersion
contao/corele3.5.30
contao/contaole4.4.7

0.002 Low

EPSS

Percentile

51.6%