Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Marten has an SQL injection vulnerability in its full-text search regConfig parameter
Vulnerability Description
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Marten SQL注入漏洞
Vulnerability Description
Marten是JasperFx开源的一款基于PostgreSQL的.NET文档数据库与事件存储工具。 Marten 8.36.1之前版本存在SQL注入漏洞,该漏洞源于全文搜索API未参数化或验证用户提供的regConfig参数,可能导致SQL注入。
CVSS Information
N/A
Vulnerability Type
N/A