Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3293-1 | modsecurity-crs security update |
Debian DLA |
DLA-4265-1 | modsecurity-crs security update |
EUVD |
EUVD-2020-15428 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T19:25:32.365Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-22669
No data.
Status : Modified
Published: 2022-09-02T18:15:11.607
Modified: 2025-11-03T20:15:45.043
Link: CVE-2020-22669
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD