{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adrogonframeworkdrogon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:drogonframework:drogon:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94143"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["drogon (\u003c= 1.9.13)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","web-application","web-application-vulnerability","sqli"],"_cs_type":"advisory","_cs_vendors":["drogonframework"],"content_html":"\u003cp\u003eThe Drogon framework, specifically versions up to 1.9.13, contains a critical SQL injection vulnerability in the Mapper::orderBy function located within the Mapper.h header of the ORM Mapper component. An attacker can reach this function by providing a malicious input to the 'sort' argument during an application request. Because the framework does not properly sanitize this input before including it in a database query, remote attackers can execute arbitrary SQL commands. This allows for unauthorized data exfiltration, database structure modification, or potential bypass of application authentication mechanisms. The vulnerability is publicly disclosed, and as of the latest intelligence, the vendor has not provided a patch to address this flaw. Defenders should prioritize identifying and restricting access to application endpoints that leverage the affected ORM Mapper functionality.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database. This can lead to full database compromise, sensitive data exfiltration, and potential unauthorized administrative access to the affected web application. Given the framework is used for high-performance C++ backend services, the exposure could affect critical business logic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize code audits to identify endpoints utilizing the Mapper::orderBy function within your applications. Since no patch is available, implement application-level input validation to sanitize or block any characters or sequences indicative of SQL injection attacks in the 'sort' parameter. Deploy WAF rules to inspect HTTP parameters for common SQL injection patterns targeting the identified argument. Monitor web server logs for irregular SQL syntax within application requests.\u003c/p\u003e\n","date_modified":"2026-09-21T08:27:03Z","date_published":"2026-09-21T06:26:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-drogon-sql-injection/","summary":"An unauthenticated remote SQL injection vulnerability in the Drogon framework ORM Mapper allows attackers to manipulate database queries via the sort parameter.","title":"SQL Injection Vulnerability in Drogon Framework ORM Mapper","url":"https://feed.craftedsignal.io/briefs/2026-09-drogon-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:drogonframework:drogon:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}