Product
JHipster-generated reactive applications are vulnerable to SQL injection via the 'sort' parameter in paginated endpoints, allowing authenticated attackers to execute arbitrary SQL commands.