PT-2026-69292 · Npm · Node-Sql-Query
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
dresende node-sql-query versions 0.1.25 through 0.1.28
Description
A SQL injection issue exists in the Request Parameter Handler component within the
lib/Select.js library. The flaw is located in the SelectQuery.from() and SelectQuery.build() functions, allowing a remote attacker to perform a manipulation that results in the execution of arbitrary SQL commands.Recommendations
Upgrade to version 0.1.29.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node-Sql-Query