CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-10752

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1040%
EPSS Percentile19.43th
Published2019年10月17日
Last Modified2024年11月21日

Vulnerability Description

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.

Affected Platforms (CPE)

📦
Sequelizejs

Sequelize

>= 4.0.0 and < 4.44.3
📦
Sequelizejs

Sequelize

>= 5.0.0 and < 5.15.1

References & Advisories

関連する脆弱性情報