SonarSource SonarQube
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*
- >= 10.4, < 10.6
A blind SQL injection vulnerability has been identified in the authorizations/group-memberships API endpoint of SonarSource SonarQube versions 10.4 through 10.5 prior to 10.6. This vulnerability allows users with the administrator role to inject SQL commands that are not visible but can be executed by the database.
Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries executed by the application, potentially leading to unauthorized data access or modification.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.