CRITICAL9.8
GHSA-68wg-qv6r-j4vp
SQL Injection in usmanhalalit/pixie
Quick fix
GHSA-68wg-qv6r-j4vp — usmanhalalit/pixie: upgrade to the fixed version with the command below.
composer require usmanhalalit/pixie:^1.0.3Details
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/usmanhalalit/pixie
Introduced in:
0Fixed in: 1.0.3Fix
composer require usmanhalalit/pixie:^1.0.3Packagist/usmanhalalit/pixie
Introduced in:
2.0.0Fixed in: 2.0.2Fix
composer require usmanhalalit/pixie:^2.0.2