Open
Description
Advisory link - GHSA-f626-677r-j5vq
What I suppose was the "source" - https://www.csirt.sk/nette-framework-vulnerability-permits-sql-injection.html
Result - all versions other than 4.0 RC are disallowed.
Imho the app allowing unfiltered user input into the DB library is the definition of app bug, not library bug, and the "vulnerability" designations seems nonsense to me, but I am no security expert.
Metadata
Metadata
Assignees
Labels
No labels