OSV 1.4.0 · unreviewed · 修改于 2026-08-30 23:30
发布时间
2026-08-30 23:30
GitHub 审查时间
—
NVD 发布时间
2026-08-30 23:16
源文件
advisories/unreviewed/2026/08/GHSA-4rc8-26x9-r9p2/GHSA-4rc8-26x9-r9p2.json
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.
该公告没有提供结构化的受影响软件包信息。