VDB
Sign up
HIGH8.8

GHSA-p74q-2pf8-j5jx

exceedone/exment and exceedone/laravel-admin SQL Injection vulnerability

Quick fix

GHSA-p74q-2pf8-j5jx — exceedone/exment: upgrade to the fixed version with the command below.

composer require exceedone/exment:^5.0.3

Details

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/exceedone/exment
Introduced in: 5.0.0Fixed in: 5.0.3
Fixcomposer require exceedone/exment:^5.0.3
Packagist/exceedone/exment
Introduced in: 0Fixed in: 4.4.3
Fixcomposer require exceedone/exment:^4.4.3
Packagist/exceedone/laravel-admin
Introduced in: 0Fixed in: 2.2.3
Fixcomposer require exceedone/laravel-admin:^2.2.3
Packagist/exceedone/laravel-admin
Introduced in: 3.0.0Fixed in: 3.0.1
Fixcomposer require exceedone/laravel-admin:^3.0.1

References