OSV 1.4.0 · unreviewed · 修改于 2026-08-27 23:31
发布时间
2026-08-27 23:31
GitHub 审查时间
—
NVD 发布时间
2026-08-27 21:18
源文件
advisories/unreviewed/2026/08/GHSA-vwjv-vcjm-rxvp/GHSA-vwjv-vcjm-rxvp.json
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the limit_videos parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.
该公告没有提供结构化的受影响软件包信息。