{"id":"CVE-2024-32231","aliases":["GHSA-75jf-52jg-qqh4","GO-2024-3070"],"url":"https://o3.security/vulnerability/CVE-2024-32231","summary":"SQL injection in github.com/stashapp/stash","details":"Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.","published":"2024-08-15T00:00:00Z","modified":"2026-08-12T03:51:37.485931310Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/stashapp/stash","fixedVersion":"0.26.0"}],"fix":{"url":"https://github.com/stashapp/stash/pull/4865","label":"stashapp/stash#4865"},"references":[{"type":"WEB","url":"https://github.com/stashapp"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32231.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32231"},{"type":"FIX","url":"https://github.com/stashapp/stash/pull/4865"},{"type":"PACKAGE","url":"https://github.com/stashapp/stash"},{"type":"WEB","url":"https://github.com/stashapp/stash/commit/89553864f5fa92beaa37a12e489064b1358d9880"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-75jf-52jg-qqh4"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-3070"},{"type":"PACKAGE","url":"github.com/stashapp/stash"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.485931310Z"}}