SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Link | Tags |
---|---|
https://bestools.group/ | product |
https://play.google.com/store/apps/details?id=freemusic.download.musicplayer.mp3player | product |
https://github.com/LianKee/SODA/blob/main/CVEs/CVE-2023-27649/CVE%20detail.md | third party advisory exploit |