PT-2018-4729 · Sailjs · Waterline-Sequel

Jamsea

·

Publicado

2018-05-29

·

Atualizado

2019-10-09

·

CVE-2016-10551

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions waterline-sequel versions 0.50
Description The issue allows malicious users to input their own SQL statements, which can be executed and provide full access to the database. This occurs when user input is passed into the like, contains, startsWith, or endsWith methods in waterline-sequel.
Recommendations Upgrade to at least version 0.5.1

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10551
GHSA-CGPP-WM2H-6HQX

Produtos afetados

Waterline-Sequel