Description
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0121 | A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to. |
Github GHSA |
GHSA-hg4c-rgvm-964g | SQL Injection in pycsw |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-17T00:31:15.280Z
Reserved: 2016-10-12T00:00:00.000Z
Link: CVE-2016-8640
No data.
Status : Modified
Published: 2018-08-01T18:29:00.220
Modified: 2024-11-21T02:59:44.623
Link: CVE-2016-8640
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA