Mapper · Mapper · CVE-2022-36594
**Name of the Vulnerable Software and Affected Versions**
Mapper versions 4.0.0 through 4.2.0
**Description**
The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the `ids` parameter at the `selectByIds` function.
**Recommendations**
For Mapper versions 4.0.0 through 4.2.0, consider restricting access to the `selectByIds` function until a patch is available. Avoid using the `ids` parameter in the affected function to minimize the risk of exploitation.