wnx/laravel-backup-restore is vulnerable to OS Command Injection
65
Medium Risk
The MySQL and PostgreSQL import commands in wnx/laravel-backup-restore concatenate database connection parameters - host, username, password, port, database name, and dump options - into a shell command without escaping them. A connection value containing shell metacharacters reaches a process run through a shell during a database restore and runs arbitrary OS commands. The patch escapes each connection parameter and dump option individually before building the import command.
You are affected if you are using a version that falls within the vulnerable range, and your database connection configuration can be influenced by untrusted input.
wnx/laravel-backup-restore is vulnerable to OS Command Injection in versions 1.1.3 - 1.9.6.
Upgrade the wnx/laravel-backup-restore library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.