Skip to content

CVE-2025-8264 - Imap - update user_identity getIdentityFromSql, to use parameters to prevent SQL Injection#161

Merged
matidau merged 1 commit intoZ-Hub:release/2.7from
matidau:cve20258264
Jul 28, 2025
Merged

CVE-2025-8264 - Imap - update user_identity getIdentityFromSql, to use parameters to prevent SQL Injection#161
matidau merged 1 commit intoZ-Hub:release/2.7from
matidau:cve20258264

Conversation

@matidau
Copy link
Copy Markdown
Collaborator

@matidau matidau commented Jul 28, 2025

Released under the GNU Affero General Public License (AGPL), version 3

What does this implement/fix? Explain your changes.

to use parameters to prevent SQL Injection
CVE-2025-8264
as reported by Snyk and XBOW

Does this close any currently open issues?

N/A
Discussion #159

Any relevant logs, error output, etc?

https://xbow.com/blog/xbow-zpush-sqli/
https://undercodetesting.com/exploiting-and-mitigating-pre-auth-blind-sql-injection-in-z-push-activesync/

to use parameters to prevent SQL Injection
CVE-2025-8264
as reported by Snyk and XBOW
@matidau matidau merged commit deb044a into Z-Hub:release/2.7 Jul 28, 2025
2 checks passed
@matidau matidau deleted the cve20258264 branch July 28, 2025 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant