VDB
Sign up
CRITICAL9.8

GHSA-3fj4-q72x-x2g9

ADOdb Library SQL Injection

Quick fix

GHSA-3fj4-q72x-x2g9 — adodb/adodb-php: upgrade to the fixed version with the command below.

composer require adodb/adodb-php:^5.20.7

Details

The `qstr` method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/adodb/adodb-php
Introduced in: 5.0Fixed in: 5.20.7
Fixcomposer require adodb/adodb-php:^5.20.7

References