A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40954.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "11.0"
},
{
"fixed": "11.0.2"
},
{
"introduced": "v12.0"
},
{
"fixed": "v12.0.2"
},
{
"introduced": "v.13.0"
},
{
"fixed": "v13.0.2"
},
{
"introduced": "v.14.0"
},
{
"fixed": "v14.0.2.1"
},
{
"introduced": "v.15.0"
},
{
"fixed": "v15.0.2"
},
{
"introduced": "v16.0"
},
{
"fixed": "v16.0.2.1"
}
],
"source": "DESCRIPTION"
}
]
}