PT-2018-5042 · Pycsw · Pycsw

Published

2018-08-01

·

Updated

2019-10-09

·

CVE-2016-8640

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pycsw versions prior to 2.0.2 pycsw versions prior to 1.10.5 pycsw versions prior to 1.8.6
Description A SQL injection issue affects the pycsw database, allowing unauthorized access to read and extract data from any table that the database user has access to. On PostgreSQL, it is also possible to perform updates, inserts, deletes, and modify the database in any table the database user has access to.
Recommendations For versions prior to 2.0.2, update to version 2.0.2 or later. For versions prior to 1.10.5, update to version 1.10.5 or later. For versions prior to 1.8.6, update to version 1.8.6 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8640
GHSA-HG4C-RGVM-964G
PYSEC-2018-98

Affected Products

Pycsw