The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bladex
Bladex springblade |
|
CPEs | cpe:2.3:a:bladex:springblade:*:*:*:*:*:*:*:* | |
Vendors & Products |
Springblade Project
Springblade Project springblade |
Bladex
Bladex springblade |

Status: PUBLISHED
Assigner: mitre
Published: 2020-07-30T19:01:59
Updated: 2024-08-04T13:37:54.174Z
Reserved: 2020-07-30T00:00:00
Link: CVE-2020-16165

No data.

Status : Modified
Published: 2020-07-30T20:15:12.737
Modified: 2025-06-03T14:38:14.490
Link: CVE-2020-16165

No data.