296,172
Total vulnerabilities in the database
A flaw in the database escaping API results in a SQL injection vulnerability when extension dbal is enabled and configured for MySQL passthrough mode in its extension configuration. All queries which use the DatabaseConnection::sql_query are vulnerable, even if arguments were properly escaped with DatabaseConnection::quoteStr beforehand.
Software | From | Fixed in |
---|---|---|
![]() |
6.2.0 | 6.2.18 |