PT-2026-96040 · Drogon · Drogon
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
drogonframework drogon versions prior to 1.9.14
Description
A remote SQL injection is possible within the ORM Mapper component. The issue resides in the
Mapper::orderBy() function located in the Mapper.h library, where improper handling of the sort variable allows for malicious manipulation of SQL queries.Recommendations
Update drogonframework drogon to version 1.9.14 or later.
As a temporary mitigation, restrict or validate the input passed to the
sort variable used in the Mapper::orderBy() function.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drogon