CVE-2018-6330: SQL Injection
Published Mar 28, 2019
·Updated
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhxuser and dhxversion parameters.
Affected Software
1 affected component
Laravel Framework=5.4.15
Event History
Mar 28, 2019
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
Description
Frequently Asked Questions
1
What is CVE-2018-6330?
CVE-2018-6330 is a vulnerability in Laravel 5.4.15 that allows Error based SQL injection in the save.php file through the dhx_user and dhx_version parameters.
2
How severe is CVE-2018-6330?
CVE-2018-6330 has a severity level of 8.8 which is considered high.
3
What software is affected by CVE-2018-6330?
Laravel Framework version 5.4.15 is affected by CVE-2018-6330.
4
How can I fix CVE-2018-6330?
To fix CVE-2018-6330, you should update Laravel to a version that is not affected by this vulnerability.
5
Where can I find more information about CVE-2018-6330?
You can find more information about CVE-2018-6330 on the following websites: [Link 1](http://www.itblog.gbonanno.de/cve-2018-6330-laravel-sql-injection/), [Link 2](https://github.com/laravel/framework/blob/5.4/CHANGELOG-5.4.md).