In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the direction
parameter and bypass ActiveRecord SQL protections.
Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication.
This is patched in wersion 0.13.0.
{ "nvd_published_at": null, "github_reviewed_at": "2020-03-13T21:05:20Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-943" ] }