Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Abel533

#25977of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2022-18817
9.8
2022-05-04
Unknown · Mybatis Pagehelper · CVE-2022-28111
**Name of the Vulnerable Software and Affected Versions** MyBatis PageHelper versions 1.x.x through 5.3.x **Description** A time-blind SQL injection vulnerability was discovered in MyBatis PageHelper via the `orderBy` parameter. This issue allows for potential SQL injection attacks. **Recommendations** For MyBatis PageHelper versions 1.x.x through 5.3.x, consider restricting access to the `orderBy` parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the `orderBy` parameter in sensitive queries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.