Description
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/94302
Patch, Third Party Advisory x_refsource_confirm
https://github.com/geopython/pycsw/pull/474/files
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2016/q4/406
Patch, Third Party Advisory x_refsource_confirm
https://patch-diff.githubusercontent.com/raw/geopython/pycsw/pull/474.patch
Scores
CVSS v3
9.1
EPSS
0.0234
EPSS Percentile
81.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-89
Status
published
Products (4)
pycsw/pycsw
< 1.8.6
pypi/pycsw
0 - 1.8.6PyPI
pypi/pycsw
1.10.0 - 1.10.5PyPI
pypi/pycsw
2.0.0 - 2.0.2PyPI
Published
Aug 01, 2018
Tracked Since
Feb 18, 2026