{"id":"GHSA-h63c-xvpf-264j","summary":"ADOdb SQL injection vulnerability","details":"The ADOdb Library for PHP prior to version 5.20.11 is prone to SQL Injection vulnerability in multiple drivers.","modified":"2024-11-29T05:39:51.874700Z","published":"2024-05-15T17:44:48Z","database_specific":{"github_reviewed_at":"2024-05-15T17:44:48Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ADOdb/ADOdb/pull/311"},{"type":"WEB","url":"https://github.com/ADOdb/ADOdb/pull/401"},{"type":"WEB","url":"https://github.com/dregad/ADOdb/commit/34788ce8c1d08500631f55764cc2247b9c7cfd2b"},{"type":"WEB","url":"https://github.com/dregad/ADOdb/commit/d29c23f2264ec95c6d3851e0f51ce240b2f36b74"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/adodb/adodb-php/2018-03-06.yaml"}],"affected":[{"package":{"name":"adodb/adodb-php","ecosystem":"Packagist","purl":"pkg:composer/adodb/adodb-php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.20.11"}]}],"versions":["v5.19","v5.20.0","v5.20.1","v5.20.10","v5.20.2","v5.20.3","v5.20.4","v5.20.5","v5.20.6","v5.20.7","v5.20.8","v5.20.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-h63c-xvpf-264j/GHSA-h63c-xvpf-264j.json"}}],"schema_version":"1.9.0"}