ZeroHour

CVE-2019-10748

PoC
CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

Vendors
sequelizejs
Products
sequelize
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.