Vulnerability Description
MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pagehelper Project | Pagehelper | >= 1.0, <= 3.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/pagehelper/Mybatis-PageHelperProductThird Party Advisory
- https://github.com/pagehelper/Mybatis-PageHelper.gitProductThird Party Advisory
- https://github.com/pagehelper/Mybatis-PageHelper/issues/674Third Party Advisory
- https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.mdExploitThird Party Advisory
- https://pagehelper.github.io/ProductThird Party Advisory
- https://www.cnblogs.com/secload/articles/16061420.htmlExploitThird Party Advisory
- https://github.com/pagehelper/Mybatis-PageHelperProductThird Party Advisory
- https://github.com/pagehelper/Mybatis-PageHelper.gitProductThird Party Advisory
- https://github.com/pagehelper/Mybatis-PageHelper/issues/674Third Party Advisory
- https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.mdExploitThird Party Advisory
- https://pagehelper.github.io/ProductThird Party Advisory
- https://www.cnblogs.com/secload/articles/16061420.htmlExploitThird Party Advisory
FAQ
What is CVE-2022-28111?
CVE-2022-28111 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
How severe is CVE-2022-28111?
CVE-2022-28111 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-28111?
Check the references section above for vendor advisories and patch information. Affected products include: Pagehelper Project Pagehelper.