OSV 1.4.0 · github-reviewed · 修改于 2021-08-27 20:54
发布时间
2021-08-31 00:12
GitHub 审查时间
2021-08-27 04:21
NVD 发布时间
2021-08-27 05:15
源文件
advisories/github-reviewed/2021/08/GHSA-79mg-4w23-4fqc/GHSA-79mg-4w23-4fqc.json
In Cachet versions through 2.3.18, there is a SQL injection which is in the SearchableTrait#scopeSearch(). Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session.
The original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.
Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability.