Tradebox 5.4 contains an SQL injection vulnerability that...
High severity
Unreviewed
Published
Mar 4, 2026
to the GitHub Advisory Database
•
Updated Mar 4, 2026
Description
Published by the National Vulnerability Database
Mar 4, 2026
Published to the GitHub Advisory Database
Mar 4, 2026
Last updated
Mar 4, 2026
Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attackers can send POST requests to the monthly_deposit endpoint with malicious symbol values using boolean-based blind, time-based blind, error-based, or union-based SQL injection techniques to extract sensitive database information.
References