Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SQL Injection Vulnerability #67

Open
Tyaoo opened this issue Jan 18, 2024 · 1 comment
Open

SQL Injection Vulnerability #67

Tyaoo opened this issue Jan 18, 2024 · 1 comment

Comments

@Tyaoo
Copy link

Tyaoo commented Jan 18, 2024

[Suggested description]
Tbed was discovered to contain a SQL injection vulnerability via the searchname parameter.

[Vulnerability Type]
SQLi

[Vendor of Product]
https://github.com/Hello-hao/Tbed

[Affected Product Code Base]
v20240111

[Affected Component]

/admin/selectPhoto

[Attack Type]
Remote

[Vulnerability details]

image

image

[Impact Code execution]
true

[Cause of vulnerability]
The searchname parameter was used in ${} format which can cause SQL Injection Vulnerability.
image

That's all, thanks.

@Hello-hao
Copy link
Owner

Thank you for raising this vulnerability. I will make improvements in the next version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants