The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Bladex
         Bladex springblade  | 
|
| CPEs | cpe:2.3:a:bladex:springblade:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Springblade Project
         Springblade Project springblade  | 
    
        
        Bladex
         Bladex springblade  | 
Status: PUBLISHED
Assigner: mitre
Published: 2020-07-30T19:01:59
Updated: 2024-08-04T13:37:54.174Z
Reserved: 2020-07-30T00:00:00
Link: CVE-2020-16165
No data.
Status : Modified
Published: 2020-07-30T20:15:12.737
Modified: 2025-06-03T14:38:14.490
Link: CVE-2020-16165
No data.
ReportizFlow