CVE-2022-28111
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
04/05/2022
Last modified:
12/12/2022
Description
MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pagehelper_project:pagehelper:*:*:*:*:*:*:*:* | 1.0 (including) | 3.7.0 (including) |
| cpe:2.3:a:pagehelper_project:pagehelper:*:*:*:*:*:*:*:* | 4.0.0 (including) | 5.0.0 (including) |
| cpe:2.3:a:pagehelper_project:pagehelper:*:*:*:*:*:*:*:* | 5.1.0 (including) | 5.3.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/pagehelper/Mybatis-PageHelper
- https://github.com/pagehelper/Mybatis-PageHelper.git
- https://github.com/pagehelper/Mybatis-PageHelper/issues/674
- https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.md
- https://pagehelper.github.io/
- https://www.cnblogs.com/secload/articles/16061420.html



