Do your applications use this vulnerable package?
Test your applications
Overview
pypostalcode is a Radius searches on Canadian postal codes, location data
Affected versions of this package are vulnerable to SQL Injection when passing user input FSA codes could delete your FSA code database.
Remediation
Upgrade pypostalcode
to version 0.3.5 or higher.
References
CVSS Score
9.4
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityLow
- Credit
- Unknown
- CWE
- CWE-89
- Snyk ID
- SNYK-PYTHON-PYPOSTALCODE-1090196
- Disclosed
- 01 Apr, 2021
- Published
- 01 Apr, 2021