{"id":"CVE-2026-69704","title":"Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()","summary":"Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL synta…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","cvssSource":"cna","cwe":["CWE-89"],"vendor":"maximeAmini","product":"Atals-Livre","affected":["Atals-Livre <= de0893f"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-05T14:53:01.579782Z"},"exploitAvailable":true,"published":"2026-08-04","updated":"2026-09-24","sourceUpdated":"2026-09-24T14:18:34.460Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-69704","references":[{"url":"https://github.com/maximeAmini/Atals-Livre","label":"Product Repository"},{"url":"https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6","label":"Github Gist"},{"url":"https://www.vulncheck.com/advisories/atals-livre-sql-injection-via-unsanitized-get-parameter-in-supp"}],"tags":["cve.org","exploit-available"],"epss":0.00276,"epssPercentile":0.20244,"ingestedAt":"2026-09-24T15:45:56.716Z","slug":"CVE-2026-69704","body":"## Overview\n\nAtals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction.\n\n## Affected\n\n- `Atals-Livre <= de0893f`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}