Junglewise Threat Intelligence

PYSEC-2019-53 - SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Severity: info · Published 2019-02-20

Technologies: SQLAlchemy (PyPI). Vendors: PyPI.

Executive brief

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Affected products

  • PyPI SQLAlchemy

Related threats