laravel-jqgrid EloquentRepositoryAbstract.php getRows sql injection
CVE-2021-4262

5.5MEDIUM

Key Information:

Vendor
CVE Published:
19 December 2022

What is CVE-2021-4262?

A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.

Affected Version(s)

laravel-jqgrid

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-4262 : laravel-jqgrid EloquentRepositoryAbstract.php getRows sql injection