← voltar
CVE-2020-11010mediumCWE-89

SQL injection in Tortoise ORM

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 6.3epss 1.0%
probabilidade de exploração
1.0%top 37% das CVEs
exploração observada
nãonenhuma fonte reporta
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Produtos afetados
tortoise · tortoise-orm