CVE-2022-31631
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Pdo, Pdo Sqlite, Php
- Php
- < 8.0.27, 8.1.15, 8.2.2
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-74
- NVD status
- Analyzed
- Published
- 2025-02-12
CVE-2022-31631 at NVD
No indexed exploits for CVE-2022-31631 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-31631 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.