CVE-2016-15021

MEDIUM

Columbia ALS Data Browser - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version v2 is able to address this issue. The identifier of the patch is cbc79a68145e845f951113d184b4de207c341599. It is recommended to upgrade the affected component. The identifier VDB-218429 was assigned to this vulnerability.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.218429
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.218429
Release Notes, Third Party Advisory patch
https://github.com/nickzren/alsdb/releases/tag/v2

Scores

CVSS v3 5.5
EPSS 0.0068
EPSS Percentile 48.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
columbia/als_data_browser 1
Published Jan 17, 2023
Tracked Since Feb 18, 2026