SQL Injection Vulnerability in Slack ArchiveBot by Docmarionum1
CVE-2018-17232

9.8CRITICAL

Key Information:

Vendor
CVE Published:
20 September 2018

What is CVE-2018-17232?

A SQL injection vulnerability exists in the Slack ArchiveBot developed by Docmarionum1. This flaw, found in archivebot.py, permits remote attackers to execute arbitrary SQL commands through manipulation of the text parameter used in the cursor.execute() function. Users running versions prior to September 19, 2018, are particularly vulnerable to this exploit, as it could allow unauthorized access to the database, potentially leading to information disclosure or data corruption.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.