Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2018-25076 Improper Neutralization of Special Elements #683

Open
PhilippSchueler5648 opened this issue Dec 10, 2024 · 0 comments
Open

Comments

@PhilippSchueler5648
Copy link

We received the following information from our OWASP-Security-Scanner:

critical severity - CVE-2018-25076 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pkg:maven/io.cloudevents/[email protected]

CVE-2018-25076 - A vulnerability classified as critical was found in Events Extension on BigTree. Affected by this vulnerability is the function getRandomFeaturedEventByDate/getUpcomingFeaturedEventsInCategoriesWithSubcategories/recacheEvent/searchResults of the file classes/events.php. The manipulation leads to sql injection. The patch is named 11169e48ab1249109485fdb1e0c9fca3d25ba01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218395.

Is this a false positive? I cannot find the actual cause of the CVE within the repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant