spryker/session is vulnerable to SQL Injection
48
Medium Risk
Affected versions of this package contain a SQL Injection vulnerability in the session deletion function due to improper sanitization of the user-supplied key parameter in the SQL query, where it is embedded using sprintf without escaping or parameterization. An attacker can exploit this by crafting a malicious key value that closes the string literal and appends additional SQL commands, potentially allowing unauthorized deletion or manipulation of session data or other database records.
You are affected if you are using a version that falls within the vulnerable range.
spryker/session is vulnerable to SQL Injection in versions 0.20.0 - 4.19.1.
Upgrade the spryker/session library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant