Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction.
https://www.vulncheck.com/advisories/atals-livre-sql-injection-via-unsanitized-get-parameter-in-supp
https://github.com/maximeAmini/Atals-Livre
https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6
Published: 2026-08-04
Updated: 2026-09-24
Base Score: 7.7
Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:C
Severity: High
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Severity: Medium
Base Score: 7
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00276