SQL Injection in usmanhalalit/pixie
Critical severity
GitHub Reviewed
Published
Nov 20, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 1.0.3
>= 2.0.0, < 2.0.2
Patched versions
1.0.3
2.0.2
Description
Reviewed
Nov 20, 2019
Published to the GitHub Advisory Database
Nov 20, 2019
Last updated
Jan 9, 2023
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
References