SQL Injection Affecting web.py package, versions [,0.39)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-WEBPY-40776
- published 5 Mar 2018
- disclosed 1 Mar 2018
- credit Unknown
How to fix?
Upgrade web.py
to version 0.39 or higher.
Overview
web.py
makes web apps .
Affected versions of this package are vulnerable to SQL Injection via the db module. The limit
and offset
vaariables could be provided by an end-user and are potentially unsafe.
References
CVSS Scores
version 3.1