The implementation of ORDER BY and GROUP BY in ZendDbSelect of ZendFramework is vulnerable to an SQL injection (CVE-2016-6233).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0272.json"