PT-2021-23223 · Galette · Galette

Published

2021-12-16

·

Updated

2021-12-21

·

CVE-2021-41262

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Galette versions prior to 0.9.6
Description Galette is a membership management web application built for non-profit organizations and released under GPLv3. The issue allows SQL injection attacks by users with member privilege. There are no known workarounds.
Recommendations For versions prior to 0.9.6, upgrade to version 0.9.6 as soon as possible to resolve the issue. As a temporary workaround, consider restricting the member privilege to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41262
GHSA-936F-XVGQ-FG74

Affected Products

Galette