Unrated severityNVD Advisory· Published Aug 4, 2026
Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()
CVE-2026-69704
Description
Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction.
Affected products
2Patches
Vulnerability mechanics
References
2- www.vulncheck.com/advisories/atals-livre-sql-injection-via-unsanitized-get-parameter-in-suppmitrethird-party-advisory
- gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6mitretechnical-description
News mentions
0No linked articles in our index yet.