Versions of the package mysql2... CVE-2024-21511

- AV AC AU C I A
发布: 2024-04-23
修订: 2024-04-23

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息