Andrey Sidorov

1 exploit Active since Apr 2024
CVE-2024-21511 WRITEUP CRITICAL WRITEUP
mysql2 < 3.9.7 - Arbitrary Code Injection via Timezone Parameter
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
CVSS 9.8