SpringBlade vulnerable to SQL injection
High severity
GitHub Reviewed
Published
Aug 29, 2023
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Aug 29, 2023
Published to the GitHub Advisory Database
Aug 29, 2023
Reviewed
Aug 31, 2023
Last updated
Nov 8, 2023
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
References