CVE-2020-5257

CVE-2020-5257

In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the `direction` parameter and bypass ActiveRecord SQL protections.

Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication.

This is patched in wersion 0.13.0.

Source: CVE-2020-5257

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다