- Reported
-
- Issued
-
- Package
-
matrix-sdk-sqlite
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#sql-injection
- Aliases
-
- References
-
- Patched
-
- Unaffected
-
- Affected Functions
- Version
matrix_sdk_sqlite::SqliteEventCacheStore::find_event_relations
-
Description
The SqliteEventCacheStore::find_event_with_relations
function constructs SQL
queries using format!()
with unescaped input, allowing an attacker to inject
arbitrary SQL. This results in a SQL injection vulnerability.
Advisory available under CC0-1.0
license.