CVE-2020-7981 is a critical SQL injection vulnerability (CWE-89) affecting the rubygeocoder geocoder library, specifically versions prior to 1.6.1. It allows unauthenticated attackers to execute Boolean-based SQL injection when the "within_bounding_box" function processes untrusted latitude and longitude data. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk of full compromise (confidentiality, integrity, and availability). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered considerable community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:rubygeocoder:geocoder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.