Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

P5092

#44548of 57,408
6.5Total CVSS
Vulnerabilities · 1
PT-2026-97115
6.5
2026-09-22
Tduckcloud · Tduck-Platform · CVE-2026-95829
**Name of the Vulnerable Software and Affected Versions** TDuckCloud tduck-platform versions prior to 5.4 **Description** Remote SQL injection is possible through the manipulation of the `orders[0].column` argument within the `PaginationInnerInterceptor.concatOrderBy()` function, located in the `tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java` file of the Pagination Inner Interceptor component. **Recommendations** Install the patch with identifier ea7f0fae7cb0fd998a3284c11addce689350cd69 for versions prior to 5.4.