CVE-2019-8979 by Fred · 21/02/2019 Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. Date published : 2019-02-21 https://github.com/huzr2018/orderby_SQLi Share this: Share on X (Opens in new window) X Share on Bluesky (Opens in new window) Bluesky Share on Facebook (Opens in new window) Facebook Share on LinkedIn (Opens in new window) LinkedIn Share on Threads (Opens in new window) Threads Share on Mastodon (Opens in new window) Mastodon Similar