mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
871 B
871 B
CVE-2019-7548
Description
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
POC
Reference
- https://github.com/no-security/sqlalchemy_test
- https://github.com/no-security/sqlalchemy_test
- https://github.com/sqlalchemy/sqlalchemy/issues/4481#issuecomment-461204518
- https://github.com/sqlalchemy/sqlalchemy/issues/4481#issuecomment-461204518
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
Github
No PoCs found on GitHub currently.