A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/emoncms/emoncms/issues/1916 |
![]() ![]() ![]() |
History
Thu, 06 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Thu, 06 Feb 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-06T20:53:20.554Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2025-22992

Updated: 2025-02-06T20:40:06.839Z

Status : Received
Published: 2025-02-06T19:15:19.970
Modified: 2025-02-06T21:15:23.317
Link: CVE-2025-22992

No data.