SQL Injection Affecting web.py package, versions [,0.39)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-WEBPY-2414096
- published 2 Mar 2022
- disclosed 2 Mar 2022
- credit Orange Tsai
How to fix?
Upgrade web.py
to version 0.39 or higher.
Overview
Affected versions of this package are vulnerable to SQL Injection via db.select
which uses limit
and offset
values directly in the query.
References
CVSS Scores
version 3.1