Impact
A SQL injection flaw exists in the PaginationInnerInterceptor.concatOrderBy method within TDuckCloud's tduck-platform, allowing an attacker to inject arbitrary SQL through the orders[0].column parameter. The flaw can be triggered remotely and could enable the attacker to read, modify, or delete data stored in the database. The vulnerability is classified under CWE-74 and CWE-89 due to improper handling of user‑supplied order clauses.
Affected Systems
Vendors: TDuckCloud; Product: tduck-platform. Versions up to 5.3 are affected. The fix is included in commit ea7f0fae7cb0fd998a3284c11addce689350cd69, which should be applied to any affected deployment.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the lack of EPSS data means exploitation probability is not quantified. The vulnerability is not listed in CISA's KEV catalog and no official workaround is provided, so the safest course is to apply the patch or upgrade. A publicly available exploit suggests that an attacker could exploit this flaw with minimal effort over the network.
OpenCVE Enrichment