CVE-2024-55586: Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method.

0.0 CVSS

Description

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method.

Classification

CVE ID: CVE-2024-55586

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: n/a

Product: n/a

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.83% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://github.com/nette/database/releases
https://www.csirt.sk/nette-framework-vulnerability-permits-sql-injection.html
https://github.com/CSIRTTrizna/CVE-2024-55586

Timeline