HIGH8.8
GHSA-p74q-2pf8-j5jx
exceedone/exment and exceedone/laravel-admin SQL Injection vulnerability
Quick fix
GHSA-p74q-2pf8-j5jx — exceedone/exment: upgrade to the fixed version with the command below.
composer require exceedone/exment:^5.0.3Details
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/exceedone/exment
Introduced in:
5.0.0Fixed in: 5.0.3Fix
composer require exceedone/exment:^5.0.3Packagist/exceedone/exment
Introduced in:
0Fixed in: 4.4.3Fix
composer require exceedone/exment:^4.4.3Packagist/exceedone/laravel-admin
Introduced in:
0Fixed in: 2.2.3Fix
composer require exceedone/laravel-admin:^2.2.3Packagist/exceedone/laravel-admin
Introduced in:
3.0.0Fixed in: 3.0.1Fix
composer require exceedone/laravel-admin:^3.0.1