CVE-2019-10748
PoC —CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
- Vendors
- sequelizejs
- Products
- sequelize
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.