A SQL injection vulnerability was found in the drogonframework drogon library up to version 1.9.13. The flaw exists in the makeCriteria function within the orm_lib/src/Criteria.cc file of the ORM component. This issue allows remote attackers to perform SQL injection attacks by manipulating the filter argument. The exploit has been made public, and although the vendor was notified, no response was received.
A vulnerability was detected in drogonframework drogon up to 1.9.13, affecting the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in SQL injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. This issue requires immediate attention from defenders and developers using the [truncated]