CRITICAL
GHSA-h63c-xvpf-264j
ADOdb SQL injection vulnerability
Quick fix
GHSA-h63c-xvpf-264j — adodb/adodb-php: upgrade to the fixed version with the command below.
composer require adodb/adodb-php:^5.20.11Details
The ADOdb Library for PHP prior to version 5.20.11 is prone to SQL Injection vulnerability in multiple drivers.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/adodb/adodb-php
Introduced in:
0Fixed in: 5.20.11Fix
composer require adodb/adodb-php:^5.20.11References
- https://github.com/ADOdb/ADOdb/pull/311[WEB]
- https://github.com/ADOdb/ADOdb/pull/401[WEB]
- https://github.com/dregad/ADOdb/commit/34788ce8c1d08500631f55764cc2247b9c7cfd2b[WEB]
- https://github.com/dregad/ADOdb/commit/d29c23f2264ec95c6d3851e0f51ce240b2f36b74[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/adodb/adodb-php/2018-03-06.yaml[WEB]