CVE detail
CVE-2020-11010 — CVE-2020-11010
Published 2020-04-20 · Modified 2026-06-17 · Vendor tortoise_orm_project · Product tortoise_orm · Source nvd
MEDIUM
severity
CVSS-derived band
0.0105
EPSS probability
exploitation probability, 30d
61.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References