CVE-2017-17920 | Ruby on Rails up to 5.1.4 reorder name sql injection (Nessus ID 232027)
A vulnerability, which was classified as critical, has been found in Ruby on Rails up to 5.1.4. This issue affects the function reorder. The manipulation of the argument name as part of Parameter leads to sql injection.
The identification of this vulnerability is CVE-2017-17920. The attack may be initiated remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.