GHSA-864j-6qpp-cmrr
CRITICALCVE-2020-7981sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when withinboundingbox is used in conjunction with untrusted swlat, swlng, nelat, or nelng data.
- Affected
- < 1.6.1
- Fixed in
- 1.6.1
- Weakness
- CWE-89
- Published
- 2020-06-10
- Source
- github