OSV 1.4.0 · unreviewed · 修改于 2026-09-01 02:31
发布时间
2026-09-01 02:31
GitHub 审查时间
—
NVD 发布时间
2026-09-01 00:19
源文件
advisories/unreviewed/2026/08/GHSA-cx8r-r225-x684/GHSA-cx8r-r225-x684.json
WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the columns parameter of the GET /api/v3/hosts endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by WAPT. By exploiting the injection point, an attacker can inject additional PostgreSQL statements, bypass the host scope restrictions applied to the account, and read information from other rows or tables within the database.
该公告没有提供结构化的受影响软件包信息。