34 known vulnerabilities, worst severity CRITICAL.
cvss
9.0
how bad it is if exploited, out of 10
epss
not scored
chance of exploitation in the next 30 days
xyz score
4.0
CyberXYZ composite, out of 10
fig. 01 — GHSA-6fqw-j3vm-7f66, the advisory selected below
// advisories
GHSA-6fqw-j3vm-7f66
CRITICAL
The implementation of ORDER BY and GROUP BY in ZendDbSelect remained prone to SQL injection when a combination of SQL expressions and comments were used. This security patch provides a comprehensive solution that identifies and removes comments prior to checking validity of the statement to ensure no SQLi vectors occur.