Junglewise Threat Intelligence

CVE-2019-7164: SQLAlchemy vulnerable to SQL Injection via order_by parameter

CVE-2019-7164 · Severity: critical · CVSS 9.8 · Published 2019-04-16

Vendors: PyPI.

Executive brief

SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x versions remain vulnerable.

Affected products

  • PyPI SQLAlchemy

References

Related threats