CVE-2019-10752
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
Affected (2)
Products: Sequelizejs: Sequelize
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0 to 4.44.3 |
References (7)
Source: report@snyk.io
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.