** DISPUTED ** SQL injection vulnerability in the 'order'...
High severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Dec 29, 2017
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Mar 21, 2024
** DISPUTED ** SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
References