-
CVSS Score
-The vulnerability involves SQL injection through API endpoint manipulation. Analysis focused on:
While exact code changes aren't visible, the pattern matches:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Umbraco.Workflow | nuget | < 10.3.9 | 10.3.9 |
| Umbraco.Workflow | nuget | >= 11.0.0-rc1, < 12.2.6 | 12.2.6 |
| Umbraco.Workflow | nuget | >= 13.0.0-rc1, < 13.0.6 | 13.0.6 |
| Plumber.Workflow | nuget | < 10.1.2 | 10.1.2 |