CyberSec.Space Logo
Back to CVE Browser

CVE-2019-10752

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1040%
EPSS Percentile19.43th
PublishedOct 17, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.

Affected Platforms (CPE)

πŸ“¦
Sequelizejs

Sequelize

>= 4.0.0 and < 4.44.3
πŸ“¦
Sequelizejs

Sequelize

>= 5.0.0 and < 5.15.1

References & Advisories

Related Vulnerabilities