craftcms/commerce is vulnerable to SQL Injection
87
High Risk
Affected versions of this package are affected by a SQL injection vulnerability in the control panel’s revenue statistics functionality. Insufficient validation of the type parameter used when constructing SQL expressions allows user-controlled values to influence the column used in a query. Because this value is interpolated into the SQL expression, a crafted request could manipulate the query executed by the application. This could allow an authenticated attacker with access to the control panel to execute unintended SQL queries.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/commerce is vulnerable to SQL Injection in versions 3.0.0 - 4.10.2 and 5.0.0 - 5.5.4.
Upgrade the craftcms/commerce library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant