SQL Injection Vulnerability in SpringBlade Framework
CVE-2020-16165
9.8CRITICAL
What is CVE-2020-16165?
The SpringBlade framework contains a SQL Injection vulnerability within its DAO/DTO implementation, specifically affecting the ORDER BY clause. This vulnerability can be exploited through the /api/blade-log/api/list endpoint by manipulating the ascs and desc parameters, potentially allowing unauthorized database access and data manipulation.
