← volver
CVE-2020-11010mediumCWE-89

SQL injection in Tortoise ORM

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.3epss 1.0%
probabilidad de explotación
1.0%top 37% de las CVE
explotación observada
noninguna fuente lo reporta
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
tortoise · tortoise-orm