SQL Injection Affecting pyorient package, versions [,1.4.7)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PYORIENT-40629
  • published15 Oct 2017
  • disclosed6 Feb 2016
  • creditPredrag Gruevski

Introduced: 6 Feb 2016

CVE NOT AVAILABLE CWE-89  (opens in a new tab)

Overview

pyorient is a Orientdb driver for python that uses the binary protocol.

Affected versions of this package vulnerable to SQL Injection. An attacker could change the WHERE clause in a query and cause it to return unexpected results.

CVSS Scores

version 3.1