CVE-2020-22784
28.04.2021, 21:15
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.Enginsight
Vendor | Product | Version |
---|---|---|
etherpad | ueberdb | 𝑥 < 1.4.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration