Vulnerability Intelligence and Management by Cybersecurity Help s.r.o.



SQL Injection: Hibernate

Using Hibernate for execution of a dynamic SQL statement built with user-controlled input allows an attacker to read and modify application data or to execute arbitrary SQL commands.