Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.
References
Link | Resource |
---|---|
https://hackerone.com/reports/311244 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-07-03 21:29
Updated : 2024-02-28 16:25
NVD link : CVE-2018-3754
Mitre link : CVE-2018-3754
CVE.ORG link : CVE-2018-3754
JSON object : View
Products Affected
query-mysql_project
- query-mysql
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')