Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3293-1 | modsecurity-crs security update |
![]() |
DLA-4265-1 | modsecurity-crs security update |
![]() |
EUVD-2020-15428 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:51:10.946Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-22669

No data.

Status : Modified
Published: 2022-09-02T18:15:11.607
Modified: 2024-11-21T05:13:21.890
Link: CVE-2020-22669

No data.

No data.