A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/c…
Medium CVSS 6.3
Summary
A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/TDuckCloud/tduck-survey-form/commit/ea7f0fae7cb0fd998a3284c11addce689350cd69
- https://vuldb.com/cve/CVE-2026-95829
- https://vuldb.com/submit/897248
- https://vuldb.com/vuln/408522
- https://vuldb.com/vuln/408522/cti
Timeline
- nvd_ingest NVD