In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
2025-02-12T22:15:29.007
2025-07-02T21:35:56.150
Analyzed
CVSSv3.1: 9.1 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 8.0.27 | Yes |
Application | php | php | < 8.1.15 | Yes |
Application | php | php | < 8.2.2 | Yes |
Application | sqlite | sqlite | ≥ 3.39.2 | No |