Description
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-79mg-4w23-4fqc | Unauthenticated SQL Injection in Cachet |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.142Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39165
No data.
Status : Modified
Published: 2021-08-26T21:15:10.053
Modified: 2024-11-21T06:18:46.087
Link: CVE-2021-39165
No data.
OpenCVE Enrichment
No data.
Github GHSA