CVE-2018-17232: Slack Archivebot Project Slack Archivebot
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
Affected products
- Slack Archivebot Project Slack Archivebot: before 2018-09-19 (fixed in 2018-09-19)
Published 2018-09-20. Last modified 2026-06-17.