VYPR

Tortoise ORM

by Tortoise ORM Project

CVEs (1)

  • CVE-2020-11010MedApr 20, 2020
    risk 0.34cvss 6.3epss 0.01

    In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and…