PT-2026-97115 · Tduckcloud · Tduck-Platform
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TDuckCloud tduck-platform versions prior to 5.4
Description
Remote SQL injection is possible through the manipulation of the
orders[0].column argument within the PaginationInnerInterceptor.concatOrderBy() function, located in the tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java file of the Pagination Inner Interceptor component.Recommendations
Install the patch with identifier ea7f0fae7cb0fd998a3284c11addce689350cd69 for versions prior to 5.4.
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tduck-Platform