{"id":"GHSA-qvw9-6567-wq78","summary":"MunkiReport reportdata module SQL injection vulnerability","details":"A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows attackers to execute arbitrary SQL commands via the req parameter of the /module/reportdata/ip endpoint.","aliases":["CVE-2020-15886"],"modified":"2024-04-24T23:11:41.806873Z","published":"2022-05-24T17:24:15Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-24T22:53:02Z","nvd_published_at":"2020-07-23T14:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15886"},{"type":"WEB","url":"https://github.com/munkireport/munkireport-php/releases"},{"type":"WEB","url":"https://github.com/munkireport/munkireport-php/releases/tag/v5.6.3"},{"type":"WEB","url":"https://github.com/munkireport/munkireport-php/wiki/20200722-SQL-Injection-In-Reportdata-Ip-In-'req'-GET-Parameter"},{"type":"PACKAGE","url":"https://github.com/munkireport/reportdata"},{"type":"WEB","url":"https://github.com/munkireport/reportdata/releases"}],"affected":[{"package":{"name":"munkireport/reportdata","ecosystem":"Packagist","purl":"pkg:composer/munkireport/reportdata"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5"}]}],"versions":["v1.1","v1.2","v1.3","v1.4","v1.5","v2.0","v2.1","v2.2","v2.3","v2.4","v2.5","v2.6","v3.0","v3.1","v3.2","v3.3","v3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qvw9-6567-wq78/GHSA-qvw9-6567-wq78.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}