social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code execution. Commit 3cabdd35c3d874608883c9eaf9bf69b2014d25c1 contains a fix for this issue.
References
Configurations
History
No history.
Information
Published : 2023-08-04 20:15
Updated : 2023-08-10 12:47
NVD link : CVE-2023-39344
Mitre link : CVE-2023-39344
CVE.ORG link : CVE-2023-39344
JSON object : View
Products Affected
fobybus
- social-media-skeleton
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')