An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

Version Information

Affected Version Fixed In
8.1 8.1.4
8.0 8.0.8
7.4 7.4.13
7.3 7.3.15

