Description
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-79mg-4w23-4fqc | Unauthenticated SQL Injection in Cachet |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.142Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39165
No data.
Status : Modified
Published: 2021-08-26T21:15:10.053
Modified: 2024-11-21T06:18:46.087
Link: CVE-2021-39165
No data.
OpenCVE Enrichment
No data.
Github GHSA