In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-04-20T21:50:13

Updated: 2020-04-20T21:50:13

Reserved: 2020-03-30T00:00:00


Link: CVE-2020-11010

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-20T22:15:13.587

Modified: 2020-04-28T17:16:24.837


Link: CVE-2020-11010

JSON object: View

cve-icon Redhat Information

No data.

CWE