CVE-2022-31631

In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-12 22:15

Updated : 2025-07-02 21:35


NVD link : CVE-2022-31631

Mitre link : CVE-2022-31631

CVE.ORG link : CVE-2022-31631


JSON object : View

Products Affected

php

  • php

sqlite

  • sqlite
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')