{"schema_version":"1.7.3","id":"GO-2025-3457","published":"2025-02-07T22:47:45Z","modified":"2026-03-03T04:56:15.520937Z","aliases":["CVE-2025-24787","GHSA-c7w4-9wv8-7x7c"],"summary":"WhoDB allows parameter injection in DB connection URIs leading to local file inclusion in github.com/clidey/whodb/core","details":"WhoDB allows parameter injection in DB connection URIs leading to local file inclusion in github.com/clidey/whodb/core","affected":[{"package":{"name":"github.com/clidey/whodb/core","ecosystem":"Go","purl":"pkg:golang/github.com/clidey/whodb/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250127202645-8d67b767e005"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3457.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/clidey/whodb/security/advisories/GHSA-c7w4-9wv8-7x7c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24787"},{"type":"WEB","url":"https://github.com/clidey/whodb/commit/8d67b767e00552e5eba2b1537179b74bfa662ee1"},{"type":"WEB","url":"https://github.com/go-sql-driver/mysql/blob/7403860363ca112af503b4612568c3096fecb466/infile.go#L128"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3457"}}