GHSA-v5wf-jg37-r9m5

    Dashboard / Vulnerabilities / GHSA-v5wf-jg37-r9m5

    GHSA-v5wf-jg37-r9m5

    Published: 21 Sept 2023Last Modified: 10 Sept 2026

    Summary: SQLpage vulnerable to public exposure of database credentials

    Details: ### Impact If - you are using a SQLPage version older than v0.11.1 - your SQLPage instance is exposed publicly - the database connection string is specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable) - the web_root is the current working directory (the default) - your database is exposed publicly then an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly. ### Patches Upgrade to [v0.11.1](https://github.com/lovasoa/SQLpage/releases/tag/v0.11.1) as soon as possible. ### Workarounds If you cannot upgrade immediately: - Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. - Using a different [web root](https://github.com/lovasoa/SQLpage/blob/main/configuration.md) (that is not a parent of the SQLPage configuration directory) fixes the issue. - And in any case, you should generally avoid exposing your database publicly ### References https://github.com/lovasoa/SQLpage/issues/89

    Affected packages

    Package

    Name: sqlpage

    Purl: pkg:cargo/sqlpage

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.11.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-v5wf-jg37-r9m5 | CVE-DB