This advisory has been withdrawn as it was reported in error. This link is maintained to preserve external references.
Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2024-12-10T16:56:06Z",
"nvd_published_at": "2024-12-10T14:30:47Z",
"severity": "MODERATE"
}