Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jaller94

#44905of 53,632
5.6Total CVSS
Vulnerabilities · 1
PT-2022-24988
5.6
2022-11-13
Unknown · Matrix-Appservice-Irc · CVE-2022-3971
**Name of the Vulnerable Software and Affected Versions** matrix-appservice-irc versions up to 0.35.1 **Description** A critical issue affects the file src/datastore/postgres/PgDataStore.ts, where the manipulation of the `roomIds` argument leads to sql injection. Upgrading to version 0.36.0 addresses this issue. **Recommendations** For matrix-appservice-irc versions up to 0.35.1, upgrade to version 0.36.0 to address the issue. As a temporary workaround, consider restricting the manipulation of the `roomIds` argument to minimize the risk of sql injection.