CVE-2015-10045

A vulnerability, which was classified as critical, was found in tutrantta project_todolist. Affected is the function getAffectedRows/where/insert/update in the library library/Database.php. The manipulation leads to sql injection. The name of the patch is 194a0411bbe11aa4813f13c66b9e8ea403539141. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218352.
References
Link Resource
https://github.com/tutrantta/project_todolist/commit/194a0411bbe11aa4813f13c66b9e8ea403539141 Patch Third Party Advisory
https://vuldb.com/?ctiid.218352 Permissions Required Third Party Advisory
https://vuldb.com/?id.218352 Permissions Required Third Party Advisory
https://github.com/tutrantta/project_todolist/commit/194a0411bbe11aa4813f13c66b9e8ea403539141 Patch Third Party Advisory
https://vuldb.com/?ctiid.218352 Permissions Required Third Party Advisory
https://vuldb.com/?id.218352 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:project_todolist_project:project_todolist:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-15 10:15

Updated : 2024-11-21 02:24


NVD link : CVE-2015-10045

Mitre link : CVE-2015-10045

CVE.ORG link : CVE-2015-10045


JSON object : View

Products Affected

project_todolist_project

  • project_todolist
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')