SQL Injection Vulnerability in Zend Framework PostgreSQL Adapter
CVE-2015-0270
9.8CRITICAL
What is CVE-2015-0270?
A vulnerability exists in the PostgreSQL adapter of the Zend Framework that could allow attackers to execute arbitrary SQL code through crafted input. This flaw affects versions of Zend Framework prior to 2.2.10 and the 2.3.x branch prior to 2.3.5. Application developers using these versions should apply the necessary updates to mitigate potential exploitation of the SQL injection risk.
Affected Version(s)
Zend Framework before 2.2.10 and 2.3.x before 2.3.5