CVE-2020-36645

Critical
|9.8
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This critical vulnerability in Square's Squalor product allows attackers to execute unauthorized SQL commands, potentially giving them access to sensitive data in the database. To be at risk, the affected system must be running a vulnerable version of the software, so it's crucial to upgrade to the latest version to protect against this threat.

Technical Description

A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version v0.0.0 is able to address this issue. The patch is named f6f0a47cc344711042eb0970cb423e6950ba3f93. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217623.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 1137 days

Quick Information

Published

Jan 7, 2023

about 3 years ago

Last Modified

Feb 18, 2026

2 days ago

Vendor

squareup

Product

squalor