Loading market data...
← Back to CVE feed

CVE-2026-100847

HIGH CVSS 7.5 View on NVD ↗

Description

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 27, 2026 02:17 UTC Modified: Sep 27, 2026 02:17 UTC