CVE-2024-55586 Information

Description

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method.

Reference

https://github.com/CSIRTTrizna/CVE-2024-55586 https://github.com/nette/database/releases https://www.csirt.sk/nette-framework-vulnerability-permits-sql-injection.html

Share on: