Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Fixe

#38025de 56,329
7.5CVSS total
Vulnerabilidades · 1
PT-2015-5244
7.5
2015-01-27
Sequelize · Sequelize · CVE-2015-1369
**Name of the Vulnerable Software and Affected Versions** sequelize versions prior to 2.0.0-rc8 **Description** A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the `order` parameter when user input is passed into it. This can be exploited by manipulating the order parameter in queries, such as in the `findAndCountAll` method. **Recommendations** Update to version 2.0.0-rc8 or later. As a temporary workaround, consider validating and sanitizing user input for the `order` parameter to prevent malicious SQL commands. Restrict access to the `order` parameter in the affected API endpoint to minimize the risk of exploitation.