CVE-2015-10045

A vulnerability, which was classified as critical, was found in tutrantta project_todolist. Affected is the function getAffectedRows/where/insert/update in the library library/Database.php. The manipulation leads to sql injection. The name of the patch is 194a0411bbe11aa4813f13c66b9e8ea403539141. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218352.
References
Link Resource
https://github.com/tutrantta/project_todolist/commit/194a0411bbe11aa4813f13c66b9e8ea403539141 Patch Third Party Advisory
https://vuldb.com/?ctiid.218352 Permissions Required Third Party Advisory
https://vuldb.com/?id.218352 Permissions Required Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:project_todolist_project:project_todolist:*:*:*:*:*:*:*:*

Information

Published : 2023-01-15 02:15

Updated : 2023-01-24 09:54


NVD link : CVE-2015-10045

Mitre link : CVE-2015-10045


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

project_todolist_project

  • project_todolist