Stock-Forecaster SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Stock-Forecaster versions through 01-04-2020. The issue arises in the portfolio() endpoint, where an attacker can send a specially crafted 'stock-symbol' parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to user data or manipulation of the application's behavior.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to interfere with the application's database queries. This could result in unauthorized data access, data manipulation, or potentially executing administrative operations on the database.

Reproduction

To reproduce this vulnerability, send a request to the portfolio() endpoint with a crafted 'stock-symbol' parameter designed to exploit SQL injection. This can be done using a tool like Burp Suite or Postman, by intercepting the request and modifying the 'stock-symbol' parameter to include SQL injection payloads.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.7
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.