PT-2019-7160 · Zend · Zend Framework

Grigory Ivanov

·

Published

2019-10-25

·

Updated

2022-05-24

·

CVE-2015-0270

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zend Framework versions 2.2.x through 2.2.9 Zend Framework versions 2.3.x through 2.3.4
Description The issue is related to a potential SQL injection in the PostgreSQL ZendDb adapter.
Recommendations For versions 2.2.x through 2.2.9, update to version 2.2.10 or later. For versions 2.3.x through 2.3.4, update to version 2.3.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0270
GHSA-V59P-P692-V382

Affected Products

Zend Framework