
CVE-2026-37505 SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to Us… https://www.cve.org/CVERecord?id=CVE-2026-37505
Post summary
The post discloses an SQL injection vulnerability in V2Board that allows unsanitized user input to be used in an ORDER BY clause, potentially leading to arbitrary data retrieval.
