OSV 1.4.0 · unreviewed · 修改于 2026-08-22 23:31
发布时间
2026-08-22 23:31
GitHub 审查时间
—
NVD 发布时间
2026-08-22 23:16
源文件
advisories/unreviewed/2026/08/GHSA-49rr-hfxh-8f4c/GHSA-49rr-hfxh-8f4c.json
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply arbitrary SQL through the filter condition, giving full read of the database.
该公告没有提供结构化的受影响软件包信息。