CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-10752

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1040%
EPSS Percentile19.43th
Published2019年10月17日
Last Modified2024年11月21日

Vulnerability Description

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.

Affected Platforms (CPE)

📦
Sequelizejs

Sequelize

>= 4.0.0 and < 4.44.3
📦
Sequelizejs

Sequelize

>= 5.0.0 and < 5.15.1

References & Advisories

相關漏洞威脅