CVE-2026-94143 | drogonframework drogon up to 1.9.13 ORM Mapper Mapper.h Mapper::orderBy sort sql injection
A vulnerability classified as critical has been found in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection.
This vulnerability is reported as CVE-2026-94143. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More