Description
SQL injection vulnerability in sqrl_verify.php in php-sqrl allows remote attackers to execute arbitrary SQL commands via the message parameter.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/69270
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Aug/49
Exploit x_refsource_confirm
https://github.com/geir54/php-sqrl/issues/4
Various Sources x_refsource_misc
https://github.com/geir54/php-sqrl/blob/0fa574520a1843a33a84c3985f934e84af6f2042/sqrl_verify.php#L39-59
Scores
EPSS
0.0135
EPSS Percentile
68.5%
Details
CWE
CWE-89
Status
published
Products (1)
php-sqrl_project/php-sqrl
Published
Aug 25, 2014
Tracked Since
Feb 18, 2026