Description
Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
2024.9.8
Credits
Fluid Attacks' AI SAST Scanner
Oscar Uribe
References
fluidattacks.com/es/advisories/motley
fluidattacks.com/es/advisories/motley
github.com/cortezaproject/corteza