Description
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
Remediation
References
Related Vulnerabilities
Weather for us-animated weather widget Crypto Mining (1.8)
My Category Order 'parentID' Parameter SQL Injection (2.8)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0825)
Email Subscribers & Newsletters Multiple Vulnerabilities (4.5.0.1)
Oracle HTTP Server CVE-2013-1862 Vulnerability (CVE-2013-1862)