### 漏洞关键信息 - **CVE Identifier**: CVE-2016-15007 - **CVSS Meta Temp Score**: 6.9 - **Current Exploit Price**: $0-$5k - **CTI Interest Score**: 0.14 #### Summary - **Vulnerability Type**: Problematic - **Affected Function**: `ObjectService` in the file `src/classes/SObjectService.cls` of the `SOQL Handler` component - **Cause**: Manipulation of the `orderDirection` argument causes injection #### Details - **Product**: Centralized-Salesforce-Dev-Framework - **Affected Component**: `SOQL Handler` - **Vulnerability Description**: The manipulation of the `orderDirection` argument with an unknown input leads to injection due to special elements not being neutralized. - **CWE**: CWE-74 - **Impact**: Affects confidentiality, integrity, and availability - **Published on**: 01/02/2023 #### Vulnerability Type and Resolution - **CVE**: CVE-2016-15007 - **Resolution**: Deploy a patch