PT-2024-20579 · Unknown · Sqlalchemyda
Perrinjerome
·
Published
2024-02-07
·
Updated
2024-02-14
·
CVE-2024-24811
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SQLAlchemyDA versions prior to 2.2
Description
A vulnerability in SQLAlchemyDA allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2.
Recommendations
For versions prior to 2.2, update to version 2.2 to resolve the issue. As a temporary workaround is not available, upgrading to the patched version is the only recommended course of action.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sqlalchemyda