{"id":"CVE-2021-4262","aliases":["GHSA-3fhj-wpvj-x5w8"],"url":"https://o3.security/vulnerability/CVE-2021-4262","summary":"laravel-jqgrid vulnerable to SQL Injection","details":"A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.","published":"2022-12-19T14:15:10.807Z","modified":"2026-07-08T06:01:21.826700229Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mgallegos/laravel-jqgrid","fixedVersion":null}],"fix":{"url":"https://github.com/mgallegos/laravel-jqgrid/commit/fbc2d94f43d0dc772767a5bdb2681133036f935e","label":"mgallegos/laravel-jqgrid@fbc2d94"},"references":[{"type":"ADVISORY","url":"https://vuldb.com/?id.216271"},{"type":"FIX","url":"https://github.com/mgallegos/laravel-jqgrid/commit/fbc2d94f43d0dc772767a5bdb2681133036f935e"},{"type":"FIX","url":"https://github.com/mgallegos/laravel-jqgrid/pull/72"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:01:21.826700229Z"}}