{"id":"GHSA-j6cv-98jx-mrwr","summary":"Mocodo vulnerable to SQL injection in `/web/generate.php`","details":"Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the `sql_case` input field in `/web/generate.php`, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.","aliases":["CVE-2024-35374","PYSEC-2026-426"],"modified":"2026-06-29T12:26:13.083506026Z","published":"2024-05-28T20:20:37Z","database_specific":{"nvd_published_at":"2024-05-24T21:15:59Z","cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-05-28T20:20:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35374"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/commit/f9368df28518b6c4a92fd207c260f1978ec34d6e"},{"type":"WEB","url":"https://chocapikk.com/posts/2024/mocodo-vulnerabilities"},{"type":"PACKAGE","url":"https://github.com/laowantong/mocodo"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158"}],"affected":[{"package":{"name":"mocodo","ecosystem":"PyPI","purl":"pkg:pypi/mocodo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.7"}]}],"versions":["2.0.0","2.0.0rc1","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.19","2.0.2","2.0.20","2.0.21","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1","2.1.2","2.1.3","2.1.4","2.3","2.3.1","2.3.2","2.3.2rc1","2.3.2rc2","2.3.3","2.3.5","2.3.7","2.3.8","2.3.9","3.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.1.0","3.1.1","3.1.2","3.2.0","3.2.1","4.0.0","4.0.1","4.0.10","4.0.11","4.0.12","4.0.13","4.0.14","4.0.2","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.1","4.1.2","4.1.3b1","4.1.3b2","4.1.3b3","4.1.3b4","4.1.3b5","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.2.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-j6cv-98jx-mrwr/GHSA-j6cv-98jx-mrwr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}