In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-04-20T21:50:13

Updated: 2024-08-04T11:21:14.257Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-04-20T22:15:13.587

Modified: 2020-04-28T17:16:24.837

Link: CVE-2020-11010

cve-icon Redhat

No data.