PT-2023-10339 · Unknown · Liftkit Database

Published

2023-01-16

·

Updated

2024-05-17

·

CVE-2016-15020

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liftkit database versions up to 2.13.1
Description A critical issue has been found, affecting the function processOrderBy of the file src/Query/Query.php. This leads to sql injection.
Recommendations For liftkit database versions up to 2.13.1, upgrade to version 2.13.2 to address this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2016-15020
GHSA-8HCF-2M4V-F2RQ

Affected Products

Liftkit Database