CVE-2016-8640

CRITICAL

pycsw <2.0.2, 1.10.5, 1.8.6 - SQL Injection

Title source: llm
STIX 2.1

Description

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94302
Patch, Third Party Advisory x_refsource_confirm
https://github.com/geopython/pycsw/pull/474/files
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2016/q4/406
Patch, Third Party Advisory x_refsource_confirm
https://patch-diff.githubusercontent.com/raw/geopython/pycsw/pull/474.patch

Scores

CVSS v3 9.1
EPSS 0.0234
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-89
Status published
Products (4)
pycsw/pycsw < 1.8.6
pypi/pycsw 0 - 1.8.6PyPI
pypi/pycsw 1.10.0 - 1.10.5PyPI
pypi/pycsw 2.0.0 - 2.0.2PyPI
Published Aug 01, 2018
Tracked Since Feb 18, 2026