CVE-2019-10766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/11/2019
Last modified:
20/11/2019

Description

Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pixie_project:pixie:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.3 (excluding)
cpe:2.3:a:pixie_project:pixie:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.2 (excluding)


References to Advisories, Solutions, and Tools