Executive brief
TDuckCloud tduck-platform is a survey and form management system. A SQL injection vulnerability in the pagination interceptor allows remote attackers to manipulate database queries through the order column parameter, potentially exposing or modifying sensitive data. Exploitation requires network access and does not require authentication.
Technical details
A SQL injection vulnerability exists in PaginationInnerInterceptor.concatOrderBy method in MybatisPlusConfig.java. The orders[0].column parameter is not properly sanitized before being concatenated into SQL queries. Remote, unauthenticated attackers can inject arbitrary SQL through crafted pagination requests to read or modify database contents.
Affected products
- TDuckCloud tduck-platform up to 5.3
Timeline
- 2026-09-23: disclosed
- 2026-07-18: patched: Patch commit ea7f0fae7cb0fd998a3284c11addce689350cd69