VDB
Sign up
HIGH8.1

GHSA-79mg-4w23-4fqc

Unauthenticated SQL Injection in Cachet

Details

### Impact In Cachet versions through 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session.

### Patches

The original repository of [https://github.com/CachetHQ/Cachet](https://github.com/CachetHQ/Cachet) is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.

Update to version 2.5 or later in the [https://github.com/fiveai/Cachet fork](https://github.com/fiveai/Cachet) to fix this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cachethq/cachet
Introduced in: 0

No fixed version published yet for cachethq/cachet (composer). Pin to a known-safe version or switch to an alternative.

References