{"id":"CVE-2022-28111","details":"MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.","aliases":["GHSA-w559-623p-vfg8"],"modified":"2026-08-27T03:48:46.358748471Z","published":"2022-05-04T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28111.json"},"references":[{"type":"WEB","url":"https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.md"},{"type":"WEB","url":"https://pagehelper.github.io/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28111.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28111"},{"type":"REPORT","url":"https://github.com/pagehelper/Mybatis-PageHelper/issues/674"},{"type":"PACKAGE","url":"https://github.com/pagehelper/Mybatis-PageHelper"},{"type":"PACKAGE","url":"https://github.com/pagehelper/Mybatis-PageHelper.git"},{"type":"ARTICLE","url":"https://www.cnblogs.com/secload/articles/16061420.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pagehelper-org/Mybatis-PageHelper","events":[{"introduced":"f3eb65f8ab7952ce674a3ddf1a02af010466ca1d"},{"last_affected":"b2a90319d4f53fe7ed0bfb4ffcd7b9eedff988c5"},{"introduced":"90c42a08b0f9596b3685d5cc44a70e95384b5c69"},{"last_affected":"e7d5af098dc9abc84712ed62390fa655dbd1f528"},{"introduced":"d20fa11f126e1ebb3e9a9b787884b59755458509"},{"last_affected":"4b0484662bae2dae121af501a84360719b5b6eb1"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:pagehelper_project:pagehelper:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0"},{"last_affected":"3.7.0"},{"introduced":"4.0.0"},{"last_affected":"5.0.0"},{"introduced":"5.1.0"},{"last_affected":"5.3.0"}]}}],"versions":["v5.3.0","v5.2.1","v5.2.0","v5.1.11","v5.1.10","v5.1.9","v5.1.8","v5.1.7","v5.1.6","v5.1.5","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.0","v4.2.1","v4.2.0","v4.1.6","v4.1.5","v4.1.4","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.3","v4.0.2","v4.0.1","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28111.json"}}],"schema_version":"1.9.0"}