CVE-2022-28111
Dashboard / Vulnerabilities / CVE-2022-28111
Summary:
Details: MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
References: https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.md, https://pagehelper.github.io/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28111.json, https://nvd.nist.gov/vuln/detail/CVE-2022-28111, https://github.com/pagehelper/Mybatis-PageHelper/issues/674, https://github.com/pagehelper/Mybatis-PageHelper, https://github.com/pagehelper/Mybatis-PageHelper.git, https://www.cnblogs.com/secload/articles/16061420.html
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- f3eb65f8ab7952ce674a3ddf1a02af010466ca1d
Fixed -None
Affected versions
v5.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
