SQL Injection in marginalia
Critical severity
GitHub Reviewed
Published
Jul 26, 2019
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Description
Published by the National Vulnerability Database
Jul 24, 2019
Reviewed
Jul 25, 2019
Published to the GitHub Advisory Database
Jul 26, 2019
Last updated
Aug 29, 2023
marginalia < 1.6 is affected by SQL Injection. The impact is an injection of any SQL queries when a user controller argument is added as a component. This issue affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is inputting of SQL to a vulnerable vector (header, http parameter, etc). The fixed version is 1.6.
References