GHSA-fcgf-j8cf-h2rm

Suggest an improvement
Source
https://github.com/advisories/GHSA-fcgf-j8cf-h2rm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-fcgf-j8cf-h2rm/GHSA-fcgf-j8cf-h2rm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fcgf-j8cf-h2rm
Aliases
Published
2022-11-01T19:00:29Z
Modified
2024-06-05T16:43:16.902595Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
IBAX go-ibax vulnerable to SQL injection
Details

A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212635.

Database specific
{
    "nvd_published_at": "2022-11-01T16:15:00Z",
    "cwe_ids": [
        "CWE-89"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-24T21:01:02Z"
}
References

Affected packages

Go / github.com/IBAX-io/go-ibax

Package

Name
github.com/IBAX-io/go-ibax
View open source insights on deps.dev
Purl
pkg:golang/github.com/IBAX-io/go-ibax

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2