criticalVulnerabilityActive
ORMar Vulnerability: Critical SQL Injection via Aggregate Functions
The Ormar ORM is vulnerable to SQL injection through min() and max() functions due to lack of input validation, allowing attackers to execute arbitrary queries.
S
SebastionCVE References
Affected
Ormar ORM versions 0.9.9 - 0.12.20.20.0b1 - 0.22.0
The Ormar ORM's min() and max() functions accept user-provided column names without validation, leading to SQL injection. This allows attackers to inject malicious queries, potentially accessing any database content. The vulnerability stems from the absence of input sanitization in get_text_clause(). Affected versions include multiple releases since 2021. Detection involves monitoring for unusual SQL patterns; mitigation requires updating Ormar or applying patches. Exploitability is high due to the critical nature and potential impact.
Sources