CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-10748

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1770%
EPSS Percentile14.75th
Published2019年10月29日
Last Modified2024年11月21日

Vulnerability Description

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

Affected Platforms (CPE)

📦
Sequelizejs

Sequelize

>= 3.0.0 and < 3.35.1
📦
Sequelizejs

Sequelize

>= 4.0.0 and < 4.44.3
📦
Sequelizejs

Sequelize

>= 5.0.0 and <= 5.8.11

References & Advisories

相关漏洞威胁