VDB
Sign up
CRITICAL9.8

GHSA-q9p4-qfc8-fvpp

SQL Injection in medoo

Quick fix

GHSA-q9p4-qfc8-fvpp — catfan/medoo: upgrade to the fixed version with the command below.

composer require catfan/medoo:^1.7.5

Details

columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/catfan/medoo
Introduced in: 0Fixed in: 1.7.5
Fixcomposer require catfan/medoo:^1.7.5

References