Impact
The vulnerability arises when MikroORM's SQL layer accepts an untrusted value for the ORDER BY direction and injects it directly into a query string. Because the direction field is not restricted, an attacker can supply raw SQL fragments that are executed by the database. This can result in blind or boolean extraction of sensitive information within the database account's privileges, compromising confidentiality of database contents.
Affected Systems
Vendors and products affected are MikroORM for Node.js. Versions prior to 6.6.16 and 7.1.7 are vulnerable. The issue impacts query builders and repository find methods that use the direction parameter in SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers; MongoDB drivers are unaffected.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity. Its EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no publicly known large-scale exploitation. Attackers would need to target applications that expose the order direction parameter to user-controlled data, typically via crafted HTTP requests or API calls. Successful exploitation requires the application to be using one of the vulnerable versions and to expose the affected query paths.
OpenCVE Enrichment