CyberSec.Space Logo
Back to CVE Browser

CVE-2019-10748

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1770%
EPSS Percentile14.75th
PublishedOct 29, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

Affected Platforms (CPE)

πŸ“¦
Sequelizejs

Sequelize

>= 3.0.0 and < 3.35.1
πŸ“¦
Sequelizejs

Sequelize

>= 4.0.0 and < 4.44.3
πŸ“¦
Sequelizejs

Sequelize

>= 5.0.0 and <= 5.8.11

References & Advisories

Related Vulnerabilities