No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | drogonframework drogon ORM Mapper Mapper.h orderBy sql injection | |
| First Time appeared |
Drogon
Drogon drogon |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:drogon:drogon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Drogon
Drogon drogon |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-21T05:15:13.281Z
Reserved: 2026-09-20T20:14:44.645Z
Link: CVE-2026-94143
No data.
No data.
No data.
OpenCVE Enrichment
No data.