CVE-2020-7981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
25/01/2020
Last modified:
27/01/2020

Description

sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubygeocoder:geocoder:*:*:*:*:*:*:*:* 1.6.1 (excluding)