cbcvebase.
CVE-2022-31631
published 2025-02-12

CVE-2022-31631: In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianphp7.4< php7.4 7.4.33-1+deb11u3 (bullseye)php7.4 7.4.33-1+deb11u3 (bullseye)
debianphp8.2< php7.4 7.4.33-1+deb11u3 (bullseye)php7.4 7.4.33-1+deb11u3 (bullseye)
phpphp>= 8.0.0 < 8.0.278.0.27
phpphp>= 8.1.0 < 8.1.158.1.15
phpphp>= 8.2.0 < 8.2.28.2.2
php_groupphp>= 8.0.x < 8.0.278.0.27
php_groupphp>= 8.1.x < 8.1.158.1.15
php_groupphp>= 8.2.x < 8.2.28.2.2

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL