Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5257

25
FAUCET Score

CVE-2020-5257 describes a SQL injection vulnerability in Administrate (rubygem) versions prior to 0.13.0. The flaw arises from insufficient validation of the 'direction' parameter during dashboard sorting, allowing an authenticated attacker to inject malicious SQL. This vulnerability carries a high severity CVSS score of 8.1, indicating high impact on confidentiality and integrity, though exploitation requires access to Administrate dashboards, which are typically authenticated. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.13.0CPE matchmatch criteria
cpe:2.3:a:thoughtbot:administrate:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
56.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0090 is in the 51st percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: administrateFixed in: 0.13.0

Vendor Advisories (1)

rubygemsGHSA-2p5p-m353-833whigh

Sort order SQL injection in Administrate

Mar 13, 2020

References

github.com / thoughtbot/administrate/commit/3ab838b83c5f565fba50e0c6f66fe4517f98eed3
PatchThird Party Advisory
github.com / thoughtbot/administrate/security/advisories/GHSA-2p5p-m353-833w
Third Party Advisory