CVE-2022-31631
CRITICAL9.1EPSS 0.60%PDO::quote() may return unquoted string
發布日:2025/2/12修改日:2026/4/28
描述
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
受影響套件(7)
- Bitnami/libphp>= 8.0.0, < 8.0.27, >= 8.1.0, < 8.1.15, >= 8.2.0, < 8.2.2
- Bitnami/php>= 8.0.0, < 8.0.27, >= 8.1.0, < 8.1.15, >= 8.2.0, < 8.2.2
- Bitnami/php-min>= 8.0.0, < 8.0.27, >= 8.1.0, < 8.1.15, >= 8.2.0, < 8.2.2
- Debian/php7.3from 0, < 7.3.31-1~deb10u3
- Debian/php7.4from 0, < 7.4.33-1+deb11u3
- Debian/php7.4from 0, < 7.4.33-1+deb11u3
- Debian/php8.2from 0, < 8.2.1-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |