Medium severity5.5NVD Advisory· Published Jan 16, 2023· Updated Jun 17, 2026
CVE-2016-15020
CVE-2016-15020
Description
A vulnerability was found in liftkit database up to 2.13.1. It has been classified as critical. This affects the function processOrderBy of the file src/Query/Query.php. The manipulation leads to sql injection. Upgrading to version 2.13.2 is able to address this issue. The patch is named 42ec8f2b22e0b0b98fb5b4444ed451c1b21d125a. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218391.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
liftkit/databasePackagist | < 2.13.2 | 2.13.2 |
Affected products
3- liftkit/databasev5Range: 2.13.0
- cpe:2.3:a:liftkit_database_library_project:liftkit_database_library:*:*:*:*:*:*:*:*Range: <2.13.2
Patches
Vulnerability mechanics
References
6- github.com/liftkit/database/commit/42ec8f2b22e0b0b98fb5b4444ed451c1b21d125anvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-8hcf-2m4v-f2rqghsaADVISORY
- github.com/liftkit/database/releases/tag/v2.13.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-15020ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryWEB
- vuldb.comnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.