VDB
Sign up
HIGH

GHSA-4mg9-vhxq-vm7j

SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database

Quick fix

GHSA-4mg9-vhxq-vm7j — laravel/framework: upgrade to the fixed version with the command below.

composer require laravel/framework:^8.40.0

Details

### Impact

Those using SQL Server with Laravel and allowing user input to be passed directly to the `limit` and `offset` functions are vulnerable to SQL injection. Other database drivers such as MySQL and Postgres are not affected by this vulnerability.

### Patches

This problem has been patched on Laravel versions 6.20.26, 7.30.5, and 8.40.0.

### Workarounds

You may workaround this vulnerability by ensuring that only integers are passed to the `limit` and `offset` functions, as well as the `skip` and `take` functions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/laravel/framework
Introduced in: 8.0.0Fixed in: 8.40.0
Fixcomposer require laravel/framework:^8.40.0
Packagist/laravel/framework
Introduced in: 0Fixed in: 6.20.26
Fixcomposer require laravel/framework:^6.20.26
Packagist/illuminate/database
Introduced in: 8.0.0Fixed in: 8.40.0
Fixcomposer require illuminate/database:^8.40.0
Packagist/illuminate/database
Introduced in: 0Fixed in: 6.20.26
Fixcomposer require illuminate/database:^6.20.26

References