SQL Injection in Geocoder
Critical severity
GitHub Reviewed
Published
Jun 10, 2020
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Reviewed
Jun 10, 2020
Published to the GitHub Advisory Database
Jun 10, 2020
Last updated
Jul 5, 2023
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when
within_bounding_box
is used in conjunction with untrustedsw_lat
,sw_lng
,ne_lat
, orne_lng
data.References