CVE-2016-15007
Centralized-Salesforce-Dev-Framework SOQL SObjectService.cls SObjectService injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler. The manipulation of the argument orderDirection leads to injection. The patch is named db03ac5b8a9d830095991b529c067a030a0ccf7b. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217195.
Se encontró una vulnerabilidad en Centralized-Salesforce-Dev-Framework. Ha sido declarada problemática. La función SObjectService del archivo src/classes/SObjectService.cls del componente SOQL Handler es afectada por esta vulnerabilidad. La manipulación del argumento orderDirection conduce a la inyección. El parche se llama db03ac5b8a9d830095991b529c067a030a0ccf7b. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217195.
In Centralized-Salesforce-Dev-Framework wurde eine problematische Schwachstelle ausgemacht. Es geht um die Funktion SObjectService der Datei src/classes/SObjectService.cls der Komponente SOQL Handler. Dank der Manipulation des Arguments orderDirection mit unbekannten Daten kann eine injection-Schwachstelle ausgenutzt werden. Der Patch wird als db03ac5b8a9d830095991b529c067a030a0ccf7b bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-01-02 CVE Reserved
- 2023-01-02 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/scottbcovert/Centralized-Salesforce-Dev-Framework/commit/db03ac5b8a9d830095991b529c067a030a0ccf7b | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Centralized Salesforce Development Framework Project Search vendor "Centralized Salesforce Development Framework Project" | Centralized Salesforce Development Framework Search vendor "Centralized Salesforce Development Framework Project" for product "Centralized Salesforce Development Framework" | < 2016-06-20 Search vendor "Centralized Salesforce Development Framework Project" for product "Centralized Salesforce Development Framework" and version " < 2016-06-20" | - |
Affected
|