Skip to content

CVE-2025-8264 - Imap - update user_identity getIdentityFromSql, to use parameters to prevent SQL Injection #162

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 28, 2025

Conversation

matidau
Copy link
Collaborator

@matidau matidau commented Jul 28, 2025

Released under the GNU Affero General Public License (AGPL), version 3

What does this implement/fix? Explain your changes.

to use parameters to prevent SQL Injection
CVE-2025-8264
as reported by Snyk and XBOW

Does this close any currently open issues?

N/A
Discussion #159

Any relevant logs, error output, etc?

https://xbow.com/blog/xbow-zpush-sqli/
https://undercodetesting.com/exploiting-and-mitigating-pre-auth-blind-sql-injection-in-z-push-activesync/

to use parameters to prevent SQL Injection
CVE-2025-8264
as reported by Snyk and XBOW
@matidau matidau merged commit 0201274 into Z-Hub:develop Jul 28, 2025
2 checks passed
@matidau matidau deleted the cve20258264dev branch July 28, 2025 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant