SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:06:49.547Z
Reserved: 2017-12-26T00:00:00
Link: CVE-2017-17920
No data.
Status : Deferred
Published: 2017-12-29T16:29:00.343
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-17920
No data.
OpenCVE Enrichment
No data.
Weaknesses