THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p6gw-4frg-j7jw (high) — WsgiDAV MySQL provider has a blind SQL injection

[GHSA] GHSA-p6gw-4frg-j7jw (high) — WsgiDAV MySQL provider has a blind SQL injection

highgithub_advisoriesPublished 2026-08-28

GHSA-p6gw-4frg-j7jw Severity: high CVE: CVE-2026-55509

WsgiDAV MySQL provider has a blind SQL injection

### Summary

The sample `MySQLBrowserProvider` builds its SQL queries by concatenating strings, and the record key from the request URL goes straight into the WHERE clause with no escaping. Any user who can reach a share backed by this provider can inject SQL through the URL. Since these read

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p6gw-4frg-j7jw