Skip to content

SQL injection vulnerability in TaxonWorks

High
LocoDelAssembly published GHSA-m9p2-jxr6-4p6c Sep 22, 2023

Package

TaxonWorks

Affected versions

< v0.33.1

Patched versions

>= 0.34.0

Description

Summary

A SQL injection vulnerability was found in TaxonWorks that allows authenticated attackers to extract arbitrary data from the TaxonWorks database (including the users table).

Impact

This issue may lead to Information Disclosure.

Severity

High

CVE ID

CVE-2023-43640

Weaknesses

Credits